Security researcher Darkster, has submitted on 07/08/2007 a cross-site-scripting (XSS) vulnerability affecting shop.npr.org, which at the time of submission ranked 3356 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 07/08/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 07/08/2007 |
Date published: 07/08/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: Darkster |
Domain: shop.npr.org |
Category: XSS |
Pagerank: 3356 |
URL: http://shop.npr.org/webapp/wcs/stores/servlet/CatalogSearchResultView?searchTerm=%22%3E%3Cscript%3Ea lert%281%29%3C%2Fscript%3E&storeId=10051&catalogId=10051&langId=-1&pageSize=6&beginIndex=0&sType=Sim pleSearch&resultType=2&searchTermScope=3&searchType=ALL&x=25&y=17 |
Click here to view the mirror
|
|
|