Security researcher haRI, has submitted on 27/05/2011 a cross-site-scripting (XSS) vulnerability affecting leads.hdfcbank.com, which at the time of submission ranked 577 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 15/06/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 27/05/2011 |
Date published: 15/06/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: haRI |
Domain: leads.hdfcbank.com |
Category: XSS |
Pagerank: 577 |
URL: https://leads.hdfcbank.com/applications/webforms/apply/cc_applynow.asp?ct=%22%3E%3CIFRAME%20SRC=%22j avascript:alert('wo07');%22%3E%3C/IFRAME%3E |
Click here to view the mirror
|
|
|