Advisory #1 (2008)
#############################
# Website: www.nasa.gov
# Bug: XSS - Cross Site Scripting
# Date: 25.03.08
#############################
Vulnerable URL: hxxp://search.nasa.gov/search/search
Click here for demo (XSS)
Fix: Validate input correctly for each and every dynamic parameter on the page. Also check the ISAPI filters, for we're still out here and looking ...
Cheers :)
Kish
Thursday, March 27, 2008
XSS in NASA website
Labels:
Crimemachine,
Hack,
Insecure,
Insecure Times,
nasa,
nasa.gov,
Web Hacking,
Whack,
XSS
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment