Security researcher aramosf, has submitted on 05/01/2011 a cross-site-scripting (XSS) vulnerability affecting www.spotify.com, which at the time of submission ranked 1386 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 09/12/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 05/01/2011 |
Date published: 09/12/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: aramosf |
Domain: www.spotify.com |
Category: XSS |
Pagerank: 1386 |
URL: https://www.spotify.com/es/get-spotify/e-card/display/?code=jijiji&template=default&sender_n ame=%3Cscript%3Ealert(%22oh%20hai%22)%3C/script%3E&recipient_name=sbd&email_message=&sen der_email=root@cert.org&recipient_email=contacto@securitybydefault.com&duration=69 |
Click here to view the mirror
|
|
|