Reflected XSS in NASA JPL Solar System Simulator

Disclosed by
cyb3rk1d
Summary by cyb3rk1d

A Reflected XSS vulnerability in the JPL Solar System Simulator (/cgi-bin/LHscript.pl) allowed arbitrary JavaScript execution via unsanitized query parameters. Demonstrated impact included a fake NASA login form to harvest credentials, and silent redirection to external sites. NASA resolved the issue by removing the vulnerable endpoint.

Activity