Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

February 7th, 2012, 09:28 GMT · By Eduard Kovacs

BLOG

Space Related Websites Found Vulnerable by Longrifle0x

SHARE:

Adjust text size:

Researcher finds XSS vulnerability in NASA's Earth website Enlarge picture - Researcher finds XSS vulnerability in NASA's Earth website
Ucha Gobejishvili, the Vulnerability Lab researcher also known as Longrifle0x, identified a number of space agency websites that contain cross-site scripting (XSS) vulnerabilities and publicly disclosed the information.

He discovered multiple flaws on subdomains owned by the National Aeronautics and Space Administration (NASA) and the European Space Agency (ESA), including lance.nasa.gov, gaia.esa.int, earth.eo.esa.int, xmm.vilspa.esa.es and earthdata.nasa.gov.

By now, after witnessing all the hacking attempts that targeted the space agencies, it shouldn’t surprise anyone that these security holes exist, but worryingly, it takes a really long time for them to patch them up.

So far, none of the vulnerabilities have been fixed.

Members of TeamHav0k found a vulnerability in a NASA website sometime last week and at the time we notified the organization, sending them an email along with a proof-of-concept. Even so, the weakness still exists today.
FILED UNDER:
XSS
NASA
ESA

TELL US WHAT YOU THINK:

1,110 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Electronic Arts Fixes XSS Vulnerability on Public Website

Facebook Game Store Exposed to SQL Injection Attacks

Researcher Finds XSS Flaws in Java, Nero and Sun Websites

Security Vulnerabilities Fixed in FAA.Gov and Oracle Solutions

XSS Vulnerability Found in Google, Forbes, Myspace, MTV and Ferrari

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM