Security researcher Venom23, has submitted on 10/09/2007 a cross-site-scripting (XSS) vulnerability affecting www.entretenimiento.co.cr, which at the time of submission ranked 62480 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 12/09/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 10/09/2007 |
Date published: 12/09/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: Venom23 |
Domain: www.entretenimiento.co.cr |
Category: XSS |
Pagerank: 62480 |
URL: http://www.entretenimiento.co.cr/entretenimiento/carrito/carrito.asp |
POST: seccion=1&codigo=4843&precio=10&descripcion=CD: O.S.T. High School Musical 2 - Soundtrack<SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>&Comprar=Comprar&cantidad=1 |
Click here to view the mirror
|
|
|