Report Email Alerts Open Bug Bounty: 205,832 coordinated disclosures
Total Vulnerabilities Fixed: 97,445
188,097 vulnerable websites, 17,723 VIP websites
4,598 security researchers, 5,928 notification subscribers

Open Bug Bounty ID

OBB-193011

reuters.com Security Vulnerability

On the 16.11.2016 security researcher bananascript Helped patch 25 vulnerabilities
Received 2 Coordinated Disclosure badges
disclosed XSS vulnerability affecting reuters.com website.

On our side, we have notified website owner via all reasonable communication channels about the vulnerability, so it can be patched as quickly as possible.

Currently the vulnerability is patched and does not represent any security risk for the website or its visitors.

Vulnerability Details


reuters.com Description

Business & Financial News, Breaking US & International News | Reuters. Reuters.com brings you the latest news from around the world, covering breaking news in business, politics, entertainment, technology, video and pictures.

Vulnerable URL:

Research's Comment:

All parameter values are reflected in unencoded form in multiple places.

Notes:

Page loads slowly when exploiting all parameters at once.

Example URL does not bypass xss auditor - test in Firefox.

Other details:

Patched:Yes, at 16.11.2016
Latest check for patch:16.11.2016 09:56 GMT
Vulnerability type:XSS
Vulnerability status:Publicly disclosed
Alexa Rank457
VIP website status:Yes
Check reuters.com for malware:Click here

Mirror: Click here to view the mirror

Coordinated Disclosure Timeline

Vulnerability reported via Full Disclosure16 November, 2016 07:22 GMT
Generic security notifications sent to website owner16 November, 2016 07:25 GMT
Vulnerability details disclosed by researcher16 November, 2016 07:25 GMT
Vulnerability patched by the website owner25 December, 2016 14:33 GMT

User Comments:

Please login via twitter to be the first one to comment.


Latest Vulnerabilities on *.reuters.com

OBB-ID Reported by Status Reported on
unpatched
29.06.2017
unpatched
15.06.2017
patched
12.03.2017
patched
10.03.2017
patched
07.02.2017
patched
16.11.2016
patched
14.11.2016
patched
02.11.2016
patched
06.09.2016
unpatched
17.05.2016
unpatched
11.05.2016
patched
09.04.2016
patched
15.10.2015
patched
15.10.2015
patched
15.10.2015
patched
29.07.2015
patched
23.07.2015
patched
28.05.2015
patched
28.05.2015
patched
28.05.2015

Latest Vulnerabilities Reported by bananascript

OBB-ID Vulnerability Status Reported
unpatched
16.06.2017
unpatched
16.06.2017
unpatched
16.06.2017
unpatched
16.06.2017
patched
12.01.2017
patched
10.01.2017
patched
10.01.2017
patched
10.01.2017
unpatched
10.01.2017
unpatched
09.01.2017
patched
08.01.2017
patched
08.01.2017
patched
08.01.2017
unpatched
07.01.2017
unpatched
07.01.2017
unpatched
06.01.2017
patched
06.01.2017
patched
06.01.2017
unpatched
06.01.2017
unpatched
06.01.2017


LATEST VIP SUBMISSIONS

mcall.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
sandiegouniontribune.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
chicagotribune.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
mangareader.net
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
nottingham.ac.uk
Reported by fakessh Helped patch 324 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
focus123.cn
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
dziennikwschodni.pl
Reported by RootByte Helped patch 433 vulnerabilities
Received 3 Coordinated Disclosure badges
on 22.01.2018
ibtimes.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
ultimate-guitar.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
espncricinfo.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018



LATEST SUBMISSIONS

premiotreccani.it
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
abcfoto.abc.es
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
konferencia.hvg.hu
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
southflorida.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
pacificsandiego.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
vagazette.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
citypaper.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
ctnow.com
Reported by deb_security Helped patch 368 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
studentaffairs.loyno.edu
Reported by fakessh Helped patch 324 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018
itcdland.csumb.edu
Reported by fakessh Helped patch 324 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 18 recommendations
on 22.01.2018