XSS vulnerability found on The New York Times website this vulnerability discovered by Hossein Hezami, they are announced this vulnerability via their twitter account.
The New York Times is an American daily newspaper, founded and continuously published in New York City since September 18, 1851. It has won 112 Pulitzer Prizes, more than any other news organization.
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in Web applications. XSS enables attackers to inject client-side script into Web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same origin policy.
You may check the reference screen shot.
I have informed this vulnerability to The New York Times, I think they will fix it as soon as possible.
The New York Times is an American daily newspaper, founded and continuously published in New York City since September 18, 1851. It has won 112 Pulitzer Prizes, more than any other news organization.
Cross-site scripting (XSS) is a type of computer security vulnerability typically found in Web applications. XSS enables attackers to inject client-side script into Web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same origin policy.
You may check the reference screen shot.
I have informed this vulnerability to The New York Times, I think they will fix it as soon as possible.
No comments:
Post a Comment