Weather Channel forecast: Bleak, with prolonged XSS

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
A billion visitors exposed to scripting storm
The Weather Channel has dammed a downpour of cross-site-scripting vulnerabilities that soaked three quarters of links on the popular site, security bod Wang Jin says.

The website received a tsunami of traffic with more than a billion unique visitors checking in each month according to Drupal which noted it was the "highest trafficked Drupal site in existence".

Wang Jin, a doctoral student at Nanyang Technological University, reported the poor conditions to the site administrators who closed the basic holes affecting tens of thousands of links late November.

Jin said attackers could have whipped up a scripting storm against visitors.

"Almost all links under the domain weather.com are (were) vulnerable to XSS attacks," Jin said in an advisory.

"Attackers just need to add script at the end of The Weather Channel's URLs [and] then the scripts will be executed.

"The reason of (sic) this vulnerability is that Weather Channel uses URLs to construct its tags without filtering malicious script codes."

Jin said 76.3 percent of links were found vulnerable using his homebrew security tool.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top