USA Today fun with XSS

USA TodayのNewsサイトに脆弱性を発見したそうです。Newsをねつ造できるんでしょうねw

"The underground hacker team CLPWN has exposed a zero-day content injection flaw in the USA Today website, allowing them to control the news content and attack the unwitting users of the popular news portal.

The news of the security breach comes at a time when both Playboy and CNN are reeling from similar “day zero” attacks on their server by the mysterious self-proclaimed “blackhat hackers”, identified only by the acronym CLPWN.