Rediff.com suffers from a cross site scripting vulnerability due to a lack of sanitizing the subject field of incoming email.
3cebcc5aa2a4f07c25bb3e97a82db04ed412f4e4aeb065ca6aed22ba6e02d0d9
*About Redif*f
Rediff.com (Nasdaq: REDF) is one of the premier worldwide online providers
of news, information, communication, entertainment and shopping services.
Rediff.com provides a platform for Indians worldwide to connect with one
another online. Rediff.com is committed to offering a personalized and a
secure surfing and shopping environment.
Rediff.com additionally offers the Indian American community one of the
oldest and largest Indian weekly newspapers, India Abroad.
Founded in 1996, Rediff.com is headquartered in Mumbai, India with offices
in New Delhi, Bangalore, Chennai, Hyderabad and New York, USA.
Mission In The Internet Space
To provide world-class online consumer service offerings to Indians
worldwide.
*
*
*Vulnerability*
Persistant XSS Vulnerability in Subject field of rediff
Vulnerability Reported on : Sat, Jan 23, 2010 at 1:23 AM
But they din't even cared to respond back .
*
*
*Credits*
This Vulnerability was discovered and reported by w4rl0ck.d0wn and Rockey
Killer of h4ck3r crew
*
*
*POC*
http://h4ck3r.in/Reported%20Vulnerabilities/rediff/
Rockey Killer
h4ck3r Crew <http://h4ck3r.in/>