
Cross-site scripting vulnerabilities were found in “The Weather Channel” affecting three-quarters of connections to the popular site.
The website had very high traffic and received more than a billion unique visitors each month, according to Drupal , which noted that it was “the most visited Drupal.”
Wang Jin, a doctoral student at Nanyang Technological University, identified and reported the website's vulnerabilities to administrators who eventually patched the security holes affecting tens of thousands of connections in late November.
Jin said the attackers could have carried out a scripting attack against the website's visitors.
“Almost all links on the weather.com are (were) vulnerable to XSS,” Jin said.
"Attackers would simply have to add a script to the end of The Weather Channel and then the scripts would be executed."
“The vulnerability exists because The Weather Channel uses URLs for its tags, without filtering out the malicious script code.”
Jin said that 76.3 percent of the links were found to be vulnerable using a proprietary security tool.
Cross-site scripting vulnerabilities allow scripts to be injected into web applications where validation is weak. It was the third most common vulnerability in web applications according to the OWASP Top Ten.
