Summary by cyb3rk1d
A Reflected XSS vulnerability in the JPL Solar System Simulator (/cgi-bin/LHscript.pl) allowed arbitrary JavaScript execution via unsanitized query parameters. Demonstrated impact included a fake NASA login form to harvest credentials, and silent redirection to external sites. NASA resolved the issue by removing the vulnerable endpoint.