Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security ) [Project Leader]

The Web Hacking Incidents Database
Last update:07 November 2007

List of incidents for 2001

Other years: 1999, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007


There are 6 incidents for 2001
WHID 2001-6: XSS at Microsoft Passport
Date: 05 November 2001
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting

References:

WHID 2001-5: Privacy hole found in Verizon Wireless Web site
Date: 06 September 2001
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Credential/Session Prediction

References:

WHID 2001-4: Hacked Web site damaged PCs in Japan
Date: 21 August 2001
Incident Type: Security Breach
WASC Threat Classification: Cross-site Scripting

Users who visited the Price Lotto site using Microsoft's IE (Internet Explorer) 4.x and 5.x, automatically downloaded malicious JavaScript that was programmed to alter the software configuration of their PCs.

References:

WHID 2001-3: Persistent XSS in Hotmail
Date: 03 August 2001
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting

Persistent XSS HTML Injection inside an HTML email message to hotmail

References:

WHID 2001-2: Computer E-Retailer Exposes Credit Card Numbers
Date: 18 June 2001
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Credential/Session Prediction

View other orders by changing a sequential parameter number. Security was provided by client side JavaScript

References:

WHID 2001-1: Travelocity exposes customer information
Date: 22 January 2001
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Predictable Resource Location

Sensitive files were left in a publicly accessible directory of a new web server install

References:




This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

© Copyright 2005, Web Application Security Consortium. All rights reserved.