Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security) [Project Leader]

The Web Hacking Incidents Database
Last update:17 February 2008

List of Incidents for a Classification

Please note that classifications are a new feature and not all entries in WHID are already classified, so when you get a certain number of entries for a classification, WHID might have more records matching that classification that we did not classify yet. We hope to complete the classification process soon.

Select classification:
Attack Method, Country, Location, Origin, Outcome, Software, Vertical

Select criteria for classification "Outcome":
Blackmail, Chaos, Deceit, Defacement, Disclosure Only, Downtime, Extortion, Identity Theft, Information Warfare, Leakage of Information, Link Spam, Loss of Sales, Monetary Loss, Phishing, Planting of Malware, Political Defacement, Spam, Worm


List of incidents for which Outcome is Disclosure Only
86 incidents listed
WHID 2008-03: FTC settles with a retailer for lack of reasonable security
Reported: 19 January 2008
Occurred: 19 January 2008

Classifications:

  • Attack Method: SQL Injection
  • Country: USA
  • Outcome: Disclosure Only
  • Vertical: Retail

An SQL injection vulnerability that could result in a hacker being able to access credit card numbers, expiration dates, and security codes of thousands of consumers was discovered in the web site of retailer "life is good".

The US Federal Trade Commission charged "life is good" with lack of reasonable and appropriate security for the sensitive consumer information stored on its servers. The company's settlement with the company requires the company to accept a very comprehensive and costly security procedure going forward.

References:

WHID 2007-78: A Brazilian banking site allows users to views receipts intended for others
Reported: 01 January 2008
Occurred: 29 January 2007

Classifications:

  • Attack Method: Credential/Session Prediction
  • Country: Brazil
  • Outcome: Disclosure Only
  • Vertical: Finance

IDG now reports a bug in the internet banking application of Unibanco, a Brazilian Bank. The vulnerability allowed logged users to view transaction receipts of other unrelated users by changing the "receipt ID" on the form or URL.

Reported by Alexandre Sieira

References:

WHID 2007-62: A security flaw in Passport Canada's website
Reported: 19 December 2007
Occurred: 01 December 2007

Classifications:

  • Attack Method: Credential/Session Prediction
  • Country: Canada
  • Outcome: Disclosure Only
  • Vertical: Government

The Web site of the Canadian passports authority enables users to access others' record by modifying a value of a parameter in the URI.

References:

WHID 2007-56: TJMaxx XSS Vulnerability
Reported: 07 November 2007
Occurred: 23 September 2007

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Country: USA
  • Outcome: Disclosure Only
  • Vertical: Retail

A small XSS vulnerably caught RSnake eyes. What makes it different, after all xssed.com lists thousands and thousands of those? What caught RSnames eyes was the vulnerable site. TJMaxx earned the reputation as the company that suffered the biggest security breach ever. You would expect them to be more careful.

References:

WHID 2004-18: Security flaw exposed in Cahoot bank accounts
Reported: 25 October 2007
Occurred: 01 November 2004

Classifications:

  • Attack Method: Insufficient Authentication
  • Attack Method: Predictable Resource Location
  • Outcome: Disclosure Only

Following a software upgrade, Cahoot, a UK based Internet only bank allowed accessing user accounts by guessing their user names. At least on one page allowed accessing an account by only specifying the user name in the URL. The bug was open for 12 days before being discovered.

The site was taken off line for 10 hours to fix the issue. It is a significant incident, as it is one of those rare occasions where vulnerability was serious enough to force the organization to just take the site off line until it is fixed.

We somehow missed this story so it finds its way to WHID only now in late 2007.

References:

WHID 2007-32: XSS vulnerability on various German online banking sites
Reported: 01 July 2007
Occurred: 17 May 2007

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Country: Germany
  • Outcome: Disclosure Only
  • Vertical: Finance

I seldom add disclosures anymore to WHID, even less XSS disclosures, but since this time they were discovered in banking sites, I thought it was worth it. After all, too many times people think that application vulnerabilities are found only at less "serious" or less "important" web sites where no real damage can occur.

References:

WHID 2007-12: SQL injection at knorr.de login page
Reported: 02 April 2007
Occurred: 02 March 2007

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Attack Method: SQL Injection
  • Country: Germany
  • Outcome: Disclosure Only
  • Vertical: Retail

While vulnerabilities in public web sites are dime a dozen this days and rarely included in WHID, a classic SQL injection in the login form on the home page of the web site of a very big company is worth an entry. In my presentation I usually claim that such vulnerabilities have disappeared years ago and then go on to show advanced SQL injection techniques. It seems that they exit.

References:

WHID 2006-39: Another Google XSS
Reported: 24 July 2006
Occurred: 04 July 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An XSS vulnerability in the feature allowing adding an arbitrary RSS to personal web pages. Since this page resides on the main www.google.com host, the executed JavaScript can access any Google resource.

References:

WHID 2006-38: Convenience or just bad design?
Reported: 24 July 2006
Occurred: 12 July 2006

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

Altiris seems to have designed their servers so that it is easy to both access their customers upload as well as find out their e-mail addresses.

References:

WHID 2006-40: Data Mining MySpace Bulletins
Reported: 24 July 2006
Occurred: 30 June 2006

Classifications:

  • Attack Method: Insufficient Authorization
  • Attack Method: Predictable Resource Location
  • Outcome: Disclosure Only

MySpace bulletins, presumably accessible only to the social network of the originator can be access by anyone by iterating through a message id query parameter.

References:

WHID 2006-34: XSS Exploit at sms.ac
Reported: 09 May 2006
Occurred: 03 January 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

This community site allows including scripts in multiple locations including ones personal profile thus enabling XSS.

References:

WHID 2006-33: Alexadex.com players.py XSS Exploit
Reported: 09 May 2006
Occurred: 04 May 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Alexadex is an online investment game. There is an XSS vulnerability in the group adding functionality.

References:

WHID 2006-32: libero.it XSS vulnerability - HTML injection
Reported: 09 May 2006
Occurred: 28 April 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Libero.it is a Web portal of big Italian ISP offering dial-up, Broadband and talk services. A script on it's customer service pages which enabled a connection speed test is vulnerable to XSS.

References:

WHID 2006-31: URL Bug On 1ASPHost and DomainDLX Hosting Services
Reported: 09 May 2006
Occurred: 05 May 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

A researcher found that the login error page on this sites can be injected.

References:

WHID 2006-35: Yahoo mail XSS in CSS expression keyword
Reported: 09 May 2006
Occurred: 21 April 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Yahoo mail does not filter properly the CSS "expression" keyword when it includes a comment that is encoded.

References:

WHID 2006-28: Tlen.PL e-mail XSS vulnerability
Reported: 20 April 2006
Occurred: 16 April 2006

Classifications:

  • Outcome: Disclosure Only

Tlen.PL is a popular Polish IM system provided by o2.pl, which includes e-mail accounts. The e-mail client is web based with a browser embedded in the communicator software. Certain webmail servers do not validate e-mail subject for HTML tags, allowing attacker to inject script code.

References:

WHID 2006-27: SQL Injection in incredibleindia.org
Reported: 20 April 2006
Occurred: 29 March 2006

Classifications:

  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

www.incredibleindia.org is official Indian government tourism website.

The researcher has found that the parameter PageID in the page ms_Page.asp is vulnerable to SQL injection. He further tested that SQL error messages enable standard probing methods for finding out the number of columns and their type work.

References:

WHID 2006-23: ICQ search vulnerable to XSS
Reported: 12 April 2006
Occurred: 10 January 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

ICQ.com search script (search_result.php) is vulnerable to cross-site scripting attacks. This problem is due to a failure in the application to properly sanitize user input, the input can be passed to the vulnerable script in 2 variables (gender and home_country_code).

References:

WHID 2006-22: SQL injection in a banking application
Reported: 12 April 2006
Occurred: 01 January 2006

Classifications:

  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

A CIO of a bank in Singapore reports that many application layer vulnerabilities, including SQL injection, where discovered in a banking application they purchased before it was put into production.

References:

WHID 2006-25: Everyone.net XSS
Reported: 12 April 2006
Occurred: 12 February 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Everyone.net login script (loginuser.pl) is prone to a cross site scripting attack in the variable loginName.

References:

WHID 2005-61: Gmail session management bug
Reported: 12 April 2006
Occurred: 18 October 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

A bug in Gmail's authentication and session management allows direct login to anybodies account without requiring any involvement of the victim.

References:

WHID 2006-24: Hotmail XSS (2)
Reported: 12 April 2006
Occurred: 20 February 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

The $a variable in Hotmail's inbox is vulnerable to cross site scripting vulnerability. Exploit requires the victim to open the email message.

References:

WHID 2006-21: Sourceforge.net XSS (1)
Reported: 12 April 2006
Occurred: 24 February 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Sourceforge download pages are vulnerable to XSS

References:

WHID 2006-20: Sourceforge.net XSS (2)
Reported: 10 April 2006
Occurred: 09 April 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Sourceforge forums search is vulnerable to XSS

References:

WHID 2006-19: Google XSS
Reported: 10 April 2006
Occurred: 04 April 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Yet another Google XSS. This time it seems to hit Arabic variant of the main search site. It seems that the actual language selector parameter enables the attack.

References:

WHID 2006-18: Myspace.com - Intricate Script Injection Vulnerability
Reported: 10 April 2006
Occurred: 05 April 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Forget putting <script> tags in input field. This high tech vulnerability exploits the code handling online/offline flags by inserting a malicious online/offline flag. Awesome.

References:

WHID 1999-1: eBay downplays security hole
Reported: 04 April 2006
Occurred: 19 April 1999

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Country: USA
  • Outcome: Disclosure Only

A very early XSS issue at eBay. Interesting historically as it seems that at the time the term XSS was not yet in use.

References:

WHID 2006-15: eBay contains a cross-site scripting vulnerability
Reported: 04 April 2006
Occurred: 04 April 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

eBay contains a cross-site scripting vulnerability. When an eBay user posts an auction, eBay allows SCRIPT tags to be included in the auction description which creates a cross-site scripting vulnerability in the eBay website

References:

WHID 2006-14: Forgotten password clues create hacker risk
Reported: 04 April 2006
Occurred: 20 March 2006

Classifications:

  • Attack Method: Weak Password Recovery Validation
  • Outcome: Disclosure Only

A UK Security Consulting firm reports that 54 UK sites that it has surveyed have flaws in the "forgotten password" feature.

References:

WHID 2006-5: Hotmail XSS (1)
Reported: 29 March 2006
Occurred: 28 January 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Hotmail's filtering engine insufficiently filters JavaScript scripts. It is possible to write JavaScript in the BGCOLOR attribute of the BODY tag, using CSS. This leads to execution when the email is viewed. JavaScript must be Unicode encoded in order to fool the filter. This encoding is recognized with IE >= 6

References:

WHID 2006-8: ICQmail.com - Mail2World.com XSS vulnerability
Reported: 05 March 2006
Occurred: 25 February 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Links sent to a user as part of the mail content are not properly sanitized, so a user receiving such mail and activating a link would be affected.

References:

WHID 2006-7: Google Reader "preview" and "lens" script improper feed validation
Reported: 05 March 2006
Occurred: 22 February 2006

Classifications:

  • Attack Method: Redirection
  • Outcome: Disclosure Only

Google reader allows redirection so sites can fool users to subscribe to malicious content.

References:

WHID 2006-11: Teenager claims to find code flaw in Gmail
Reported: 05 March 2006
Occurred: 02 March 2006

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

A 14 years old claims to have discovered an XSS flaw in Google's Gmail. Comments have been mixed, and Google did not comment, so either the flaw was fixed pretty fast, or did not exits.

References:

WHID 2005-49: Google Base launched with security hole
Reported: 28 February 2006
Occurred: 21 November 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

XSS in Google Base search function

References:

WHID 2005-50: XSS on Yahoo Mail
Reported: 28 February 2006
Occurred: 23 November 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Inserting code in an HTML attachments enables changing the user interface of Yahoo mail, which may enable fraud.

References:

WHID 2005-59: Vote Someone Else's Shares
Reported: 28 February 2006
Occurred: 24 December 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Attack Method: Insufficient Authentication
  • Outcome: Disclosure Only

Janus mutual fund uses predictable identifier to authenticate its share holders enabling them to vote for others.

References:

WHID 2005-55: Yahoo RSS XSS Vulnerability
Reported: 28 February 2006
Occurred: 18 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

A malicious site can offer users a malformed RSS XML file to be included Yahoo RSS aggregation that would enable stealing Yahoo cookies

References:

WHID 2005-51: Critical MySpace Vulnerabilities Leave Every Active Account Exploitable
Reported: 28 February 2006
Occurred: 05 December 2005

Classifications:

  • Attack Method: Abuse of Functionality
  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An XSS when receiving notification of an incoming IM message. Additionally it is possible to send an IM message to somebody who has blocked such messages by pretending to be answering a message from him.

References:

WHID 2005-56: XSS vulnerabilities in Google.com
Reported: 28 February 2006
Occurred: 21 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

A redirection to an error page on Google.com includes values sent by the the user. This vulnerability allows phishers to send an e-mail with links to Google that will include their attack page.

References:

WHID 2005-58: Yahoo mail Cross Site Scripting
Reported: 28 February 2006
Occurred: 22 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An attacker can send an e-mail with a malicious script to a victim which is perform its actions immediately when the e-mail is read.

References:

WHID 2005-60: KU shuts down housing application Web site
Reported: 26 February 2006
Occurred: 27 December 2005

Classifications:

  • Attack Method: Unknown
  • Outcome: Disclosure Only

Web site used to file online for housing at KU was shutdown for lack of proper security measures to prevent visitors from viewing personal information about others

References:

WHID 2005-54: XSS vulnerability in NIST web site
Reported: 26 February 2006
Occurred: 14 December 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Netcraft discovered an XSS vulnerability in NIST web site, which ironically hosts the U.S. National Vulnerability Database.

References:

WHID 2006-1: Google's Blogger HRS vulnerability
Reported: 26 February 2006
Occurred: 02 January 2006

Classifications:

  • Attack Method: HTTP Response Splitting
  • Outcome: Disclosure Only

References:

WHID 2006-2: GSA takes down eOffer after finding security flaw
Reported: 26 February 2006
Occurred: 13 January 2006

Classifications:

  • Attack Method: Insufficient Authorization
  • Attack Method: Predictable Resource Location
  • Outcome: Disclosure Only

Documents uploaded to GSA site where accessed using a predictable sequential identifier without requiring special permissions. The documents where available both for viewing and modifying. The site was in service for more than 18 months until the vulnerability was discovered.

References:

WHID 2005-20: Security gaps found in EPA contracting system
Reported: 26 February 2006
Occurred: 01 July 2005

Classifications:

  • Attack Method: Known Vulnerability
  • Outcome: Disclosure Only

An audit of a major Environmental Protection Agency contract management system uncovered significant security lapses that, if exploited by hackers, could have serious consequences for the agency's operations, assets and personnel. The audit focused on lack of monitoring for known vulnerabilities on these systems.

References:

WHID 2005-48: Insufficient authorization on Papa John's Pizza chain web site
Reported: 10 November 2005
Occurred: 07 November 2005

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

References:

WHID 2005-43: XSS in Yahoo's Web mail enables phishing
Reported: 10 November 2005
Occurred: 21 October 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

XSS in Yahoo mail, Allows phishing

References:

WHID 2005-42: Default password in a common application used by schools
Reported: 10 November 2005
Occurred: 21 October 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Outcome: Disclosure Only

The software has a default password for teachers, enabling anyone to access the system with teachers privileges.

References:

WHID 2005-41: XSS on Google's AdWords enables phishing
Reported: 10 November 2005
Occurred: 10 October 2005

Classifications:

  • Attack Method: Other
  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

References:

WHID 2005-14: XSS on Microsoft Xbox site allowed phishing
Reported: 08 November 2005
Occurred: 25 May 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

References:

WHID 2005-33: Insufficient authorization on Verizon's MyAccount feature
Reported: 22 August 2005
Occurred: 12 August 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

A web site flaw could have allowed a user to view another subscriber's balance of remaining airtime minutes and the number of minutes that customer had used in the current billing cycle

References:

WHID 2005-32: Weak password recovery on Citrix's site
Reported: 08 August 2005
Occurred: 03 August 2005

Classifications:

  • Attack Method: Weak Password Recovery Validation
  • Outcome: Disclosure Only

Weak password recovery procedure at Citrix

References:

WHID 2004-2: Biggest Web Problem Isn't About Privacy, It's Sloppy Security - Saks
Reported: 04 August 2005
Occurred: 26 January 2004

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

References:

WHID 2004-6: More Scary Tales Involving Big Holes In Web-Site Security - Tiffany
Reported: 04 August 2005
Occurred: 02 February 2004

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

References:

WHID 2004-5: More Scary Tales Involving Big Holes In Web-Site Security - Gateway
Reported: 04 August 2005
Occurred: 02 February 2004

Classifications:

  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

References:

WHID 2004-3: More Scary Tales Involving Big Holes In Web-Site Security - Iomega
Reported: 04 August 2005
Occurred: 02 February 2004

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

References:

WHID 2004-4: More Scary Tales Involving Big Holes In Web-Site Security - Kohl's
Reported: 04 August 2005
Occurred: 02 February 2004

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

References:

WHID 2004-7: More Scary Tales Involving Big Holes In Web-Site Security - University Sub Service
Reported: 04 August 2005
Occurred: 02 February 2004

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

References:

WHID 2004-1: Biggest Web Problem Isn't About Privacy, It's Sloppy Security - OpenTable
Reported: 04 August 2005
Occurred: 26 January 2004

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

References:

WHID 2001-5: Privacy hole found in Verizon Wireless Web site
Reported: 04 August 2005
Occurred: 06 September 2001

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

References:

WHID 2005-26: NISCC reveals SAP R/3 security flaw
Reported: 31 July 2005
Occurred: 28 July 2005

Classifications:

  • Attack Method: Path Traversal
  • Outcome: Disclosure Only

References:

WHID 2005-29: Security issues in interactive hotel TVs
Reported: 31 July 2005
Occurred: 30 July 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

While not strictly web security, this discussion of hotel rooms TV application security is a very good example of the dangers of our networked society

References:

WHID 2004-12: XSS in Gmail
Reported: 11 July 2005
Occurred: 27 October 2004

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An XSS was found in G-Mail

References:

WHID 2004-16: Lycos Free Email XSS
Reported: 11 July 2005
Occurred: 27 December 2004

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An XSS was found in Lycos Web Mail

References:

WHID 2005-1: Gmail Bug Exposes E-mails messages of other users
Reported: 11 July 2005
Occurred: 12 January 2005

Classifications:

  • Attack Method: Unknown
  • Outcome: Disclosure Only

Parameter tampering enabled exposing sensitive information in G-Mail

References:

WHID 2005-2: Froogle XSS
Reported: 11 July 2005
Occurred: 14 January 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An XSS was found in Froogle

References:

WHID 2005-9: Undisclosed application security issue on Cisco's site forces global passwords reset
Reported: 08 April 2005
Occurred: 08 March 2005

Classifications:

  • Attack Method: Unknown
  • Outcome: Disclosure Only

An undisclosed application security issue on Cisco web site required resetting passwords for all registered users.

References:

WHID 2005-21: Insufficient authentication on USC admissions site allowed access to applicants data
Reported:
Occurred: 05 July 2005

Classifications:

  • Attack Method: SQL Injection
  • Attack Method: OS Commanding
  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

A person who discovered an SQL injection vulnerability in a USC system and informed security focus about the flaw was criminally charged with breaking into the system.

References:

WHID 2005-17: Leakage of information due to XSS in Hotmail
Reported:
Occurred: 04 June 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

References:

WHID 2005-15: Unprotected information on the University of Chicago web site
Reported:
Occurred: 27 May 2005

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

Files containing sensitive information left unprotected on the web server

References:

WHID 2005-19: Privacy Fears due to insufficient authentication on CVS drugstore chain web site
Reported:
Occurred: 27 June 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

References:

WHID 2005-12: Insufficient authentication on Arbela mutual insurance allowed access to private data
Reported:
Occurred: 05 May 2005

Classifications:

  • Attack Method: Insufficient Authentication
  • Outcome: Disclosure Only

Extranet system accessible to the public

References:

WHID 2005-6: Tampering with parameters allows access to others account data on PayMaxx Inc. site
Reported:
Occurred: 23 February 2005

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

Parameter tampering enabled jumping into someone else's account data on PayMaxx Inc. site

References:

WHID 2003-8: SQL Injection in PetCo.com leads to FTC investigation
Reported:
Occurred: 05 December 2003

Classifications:

  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

References:

WHID 2004-9: Billing and personal information leakage due to lack of authentication on a phone company web site
Reported:
Occurred: 14 June 2004

Classifications:

  • Attack Method: Insufficient Authentication
  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

A billing information system required only phone number and zip code to pull up account details

References:

WHID 2003-7: Victoria's Secret reveals far too much
Reported:
Occurred: 24 October 2003

Classifications:

  • Attack Method: Insufficient Authorization
  • Outcome: Disclosure Only

View other customers orders by changing a sequential number within a URL parameter

References:

WHID 2003-4: SQL injection on Guess site triggers an FTC inquiry
Reported:
Occurred: 18 June 2003

Classifications:

  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

References:

WHID 2003-3: User passwords could be stolid in Microsoft's Passport service
Reported:
Occurred: 08 May 2003

Classifications:

  • Attack Method: Weak Password Recovery Validation
  • Outcome: Disclosure Only

References:

WHID 2003-1: FTD.com hole leaks personal information
Reported:
Occurred: 13 February 2003

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

View other customers information by modifying a cookie

References:

WHID 2002-1: Flawed authentication at BN.com exposes personal information
Reported:
Occurred: 09 July 2002

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

Opening an account with a discontinued e-mail address exposes all the information of the discontinues account

References:

WHID 2001-6: XSS at Microsoft Passport
Reported:
Occurred: 05 November 2001

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

References:

WHID 2001-3: Persistent XSS in Hotmail
Reported:
Occurred: 03 August 2001

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

Persistent XSS HTML Injection inside an HTML email message to hotmail

References:

WHID 2001-2: Computer E-Retailer Exposes Credit Card Numbers
Reported:
Occurred: 18 June 2001

Classifications:

  • Attack Method: Credential/Session Prediction
  • Outcome: Disclosure Only

View other orders by changing a sequential parameter number. Security was provided by client side JavaScript

References:

WHID 2001-1: Travelocity exposes customer information
Reported:
Occurred: 22 January 2001

Classifications:

  • Attack Method: Predictable Resource Location
  • Outcome: Disclosure Only

Sensitive files were left in a publicly accessible directory of a new web server install

References:

WHID 2005-4: An Israeli debate site vulnerable to XSS
Reported:
Occurred: 16 February 2005

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Outcome: Disclosure Only

An Israeli public debates site called Hyde Park has an XSS vulnerability that exposes session cookies.

References:

WHID 2004-10: SQL Injection and XSS on presidential campaign web sites
Reported:
Occurred: 30 June 2004

Classifications:

  • Attack Method: Cross Site Scripting (XSS)
  • Attack Method: SQL Injection
  • Outcome: Disclosure Only

References:



This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

 
© Copyright 2005, Web Application Security Consortium. All rights reserved.