truste.org is susceptible to cross site scripting flaws.
76d0098145229faa2de84016e96ea7c0a415314736ee1baafb2ca0847c857008
Website: https://truste.org
Background:
TRUSTe® is an independent, nonprofit organization dedicated to
enabling individuals and organizations to establish trusting
relationships based on respect for personal identity and information
in the evolving networked world.
Through extensive consumer and Web site research and the support and
guidance of many established companies and industry experts, TRUSTe
has earned a reputation as the leader in promoting privacy policy
disclosure, informed user consent, and consumer education.
TRUSTe's members include eBay, Apple, MSN, NYTimes and many other big,
scary corporations.
Description: Truste's 'ivalidate.php' is used to validate "trusted"
sites. Whilst the script does add slashes to quotes and closes
<script> and <style> tags, there are a number of HTML tags it does not
strip, including <linK>,<div>,<iframe>.
This leaves the site open to attack from phishers wanting to make
their site appear "trusted".
Further information can be found here: https://wheresthebeef.co.uk/XSS/
TrustE.org were informed of the vulnerability through various e-mail
addresses 5 days ago, they are yet to respond or fix the problem.