Weather Channel Web Site Vulnerable to Reflected Cross-Site Scripting (XSS)
Popular Weather Channel web site (Weather.com) has been found to be vulnerable to a reflected Cross-Site Scripting flaw, according to researcher Wang Jing’s research. The vulnerability lies in that Weather.com does not filter malicious script codes when constructing HTML tags with its URLs. This way, an attacker just adds a malicious script at the end of the URL and executes it.
“If The Weather Channel’s users were exploited, their Identity may be stolen,” Jing said via email. “At the same time, attackers may use the vulnerability to spy users’ habits, access sensitive information, alter browser functionality, perform denial of service attacks, etc.”
Wang is a Ph.D student from School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore.
Related News:
http://www.shopyourway.com/articles/229824
http://packetstormsecurity.com/files/129288/weatherchannel-xss.txt
http://www.theregister.co.uk/2014/12/01/weather_channel_forecast_bleak_with_a_chance_of_xss/
http://ithut.tumblr.com/post/104659802158/whitehatview-the-weather-channel-fixes-web-app
http://w8sdz.tumblr.com/post/103849047220/weather-channel-web-site-vulnerable-to-reflected
http://www.securitylab.ru/news/462524.php
https://www.pinterest.com/pin/465278205228184261/
https://www.facebook.com/websecuritiesnews/posts/699866823466824
http://www.cio.com/article/2853294/weathercom-fixes-web-application-vulnerabilities.html
http://www.pcworld.com/article/2853292/weathercom-fixes-web-application-vulnerabilities.html
http://www.computerworld.com/article/2852502/weathercom-fixes-web-app-flaws.html
https://www.secnews.gr/weather-channel-xss
http://www.networkworld.com/article/2853293/weathercom-fixes-web-application-vulnerabilities.html
评论