家庭小木屋

家是什么?众说纷纭。社会学家说,家是社会的最小细胞;婚姻学家说,家是风雨相依的两人世界;文学家说,家是宝盖下面养着的一群猪……究竟什么是家呢?记得在一个朋友的结婚典礼上司仪饱含深情的那句话:家不是讲理的地方,家不是放钱的地方,家不是两个人凑合过日子的地方……

文豆 & 文库:

醉雨他乡游的喜欢:

白帽子计算机安全:

Weather Channel Web Site Vulnerable to Reflected Cross-Site Scripting (XSS) 


Popular Weather Channel web site (Weather.com) has been found to be vulnerable to a reflected Cross-Site Scripting flaw, according to researcher Wang Jing’s research. The vulnerability lies in that Weather.com does not filter malicious script codes when constructing HTML tags with its URLs. This way, an attacker just adds a malicious script at the end of the URL and executes it.


“If The Weather Channel’s users were exploited, their Identity may be stolen,” Jing said via email. “At the same time, attackers may use the vulnerability to spy users’ habits, access sensitive information, alter browser functionality, perform denial of service attacks, etc.”


Wang is a Ph.D student from School of Physical and Mathematical Sciences, Nanyang Technological University, Singapore.




Related News:

http://www.scmagazine.com/the-weather-channels-website-found-vulnerable-to-xss-attacks/article/386010/

http://www.hotforsecurity.com/blog/weather-channel-web-site-vulnerable-to-reflected-cross-site-scripting-xss-10906.html

http://www.shopyourway.com/articles/229824

http://packetstormsecurity.com/files/129288/weatherchannel-xss.txt

http://www.theregister.co.uk/2014/12/01/weather_channel_forecast_bleak_with_a_chance_of_xss/

http://tetraph.com/security/xss-vulnerability/the-weather-channel-weather-com-almost-all-links-vulnerable-to-xss-attacks/

http://ithut.tumblr.com/post/104659802158/whitehatview-the-weather-channel-fixes-web-app

http://www.inzeed.com/kaleidoscope/xss-vulnerability/the-weather-channel-weather-com-almost-all-links-vulnerable-to-xss-attacks/

https://securitypitch.com/about-group-about-com-content-network-vulnerable-to-xss-iframe-injection-security-attacks-433/

http://w8sdz.tumblr.com/post/103849047220/weather-channel-web-site-vulnerable-to-reflected

http://www.securitylab.ru/news/462524.php

https://www.pinterest.com/pin/465278205228184261/

http://sensorstechforum.com/75-of-the-websites-on-weather-com-vulnerable-to-cross-site-scripting-attacks/

https://www.facebook.com/websecuritiesnews/posts/699866823466824

http://www.cio.com/article/2853294/weathercom-fixes-web-application-vulnerabilities.html

http://www.pcworld.com/article/2853292/weathercom-fixes-web-application-vulnerabilities.html

http://www.computerworld.com/article/2852502/weathercom-fixes-web-app-flaws.html

https://www.secnews.gr/weather-channel-xss

http://www.networkworld.com/article/2853293/weathercom-fixes-web-application-vulnerabilities.html


评论

热度(17)