Information --------------------------------- Name : XSS Vulnerability in WEIBO.COM Vendor Homepage : http://corp.sina.com.cn/eng/sina_index_eng.htm Vulnerability Type : Cross-Site Scripting Severity : High Researcher : Yuping Li at ADLab of Beijing Leadsec Technology Co., Ltd Description --------------------------------- WEIBO.COM is the largest twitter-like website in China, which claimed to have more than 200 million users in 2011. It was operated by SINA Corporation (USA, Nasdaq: Sina), which is an online media company for China and Chinese Community around the world. Weibo is one of SINA's four major business lines. Details --------------------------------- ADLab (Leadsec) has discovered vulnerability in WEIBO.COM, which can be exploited to perform cross-site scripting attacks, potentially affect large number of users. Example PoC urls are as follows : http://weibo.com/mobile/cellphone?ky=iphone ">&refer=help Actually, the refer parameter can be removed : http://weibo.com/mobile/cellphone?ky= "> Successful exploitation of this vulnerability requires that victim is logged-in to the vulnerable website. Solution --------------------------------- Fix the code. Advisory Timeline -------------------- 06/01/2012 - First indirectly contact: Sent the vulnerability details 09/01/2011 - Vulnerability partially fixed, still vulnerable 12/01/2012 - Second directly contact: Sent the vulnerability details 13/02/2012 - Vulnerability Released Credits --------------------------------- Attack and Defense Lab, Beijing Leadsec Technology Co., Ltd ( http://www.leadsec.com.cn/en/index.html) References --------------------------------- Vendor Url : http://corp.sina.com.cn/eng/sina_index_eng.htm Disclaimer --------------------------------- The information provided in this advisory is provided as it is without any warranty. Leadsec disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Leadsec or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits or special damages, even if Leadsec or its suppliers have been advised of the possibility of such damages. Some countries do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply. Any modified copy or reproduction, including partially usages, of this file requires authorization from Leadsec. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of other media, are reserved by Leadsec or its suppliers. Copyright © 2012 | Beijing Leadsec Technology Co., Ltd