Security researcher LostBrilliance, has submitted on 20/02/2011 a cross-site-scripting (XSS) vulnerability affecting audience.cnn.com, which at the time of submission ranked 53 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 21/02/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 20/02/2011 |
Date published: 21/02/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: LostBrilliance |
Domain: audience.cnn.com |
Category: XSS |
Pagerank: 53 |
URL: http://audience.cnn.com/services/money/flow/sso-idProvider;?_flowExecutionKey=%3Cscript%3Ealert%28do cument.cookie%29%3C/script%3E |
Click here to view the mirror
|
|
|