Search This Blog

Powered by Blogger.

Blog Archive

Labels

XSS vulnerability found in Huffingtonpost, EA, imageshack, NYTimes:TeamHav0k


A Hacker group named "TeamHav0k" discovered XSS vulnerabilities in some high profile websites including EA,ImageShack,NyTimes,huffingtonpost.

The following sites are affected by XSS attack:
https://www22.verizon.com
http://www.huffingtonpost.com/
http://indico.cern.ch/
http://help.ea.com/
http://www.statshow.com/
http://img818.imageshack.us/
https://secure.its.yale.edu/
https://womenandscience.rockefeller.edu/
https://www-s2.education.illinois.edu/
http://www.gse.harvard.edu/
http://www.drpepper.com/
http://gamebattles.majorleaguegaming.com/
http://www.ign.com/
http://video.nytimes.com/

Poc for huffingtonpost:

http://www.huffingtonpost.com/2012/01/15/laura-kaeppeler-miss-america_n_1207088.html?ref=mostpopular"><script>alert(String.fromCharCode(84, 101, 97, 109, 72, 97, 118, 48, 107))</script>

The poc for other sites can be found here:
http://pastebin.com/vwdGRt8v

Share it:

Vulnerability

Web Application Vulnerability

XSS Vulnerability