Security researcher Bl4cKM4g1c, has submitted on 02/09/2007 a cross-site-scripting (XSS) vulnerability affecting onearth.jpl.nasa.gov, which at the time of submission ranked 795 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 07/09/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 02/09/2007 |
Date published: 07/09/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: Bl4cKM4g1c |
Domain: onearth.jpl.nasa.gov |
Category: XSS |
Pagerank: 795 |
URL: http://onearth.jpl.nasa.gov/browse.cgi?wms_server="><script>alert("XSS By Bl4cK M4g1c")</script>&layers=modis,global_mosaic&srs=EPSG:4326&width=1000&height=500&bbox=-180,-90,180,90 &format=image/jpeg&styles=&zoom= |
Click here to view the mirror
|
|
|