Websites belonging to UK’s national security agency, the MI5 (Millitary Intelligence, Section 5) and the WHO (WHO) have been found vulnerable to cross-site scripting attacks. The weaknesses allow attackers to inject rogue IFrames, prompt JavaScript alerts or redirect visitors to other potentially malicious Web pages. The MI5 website is located in the search form, which allows passing code as a search string. The WHO website has a very similar problem, with the same flaw being exploited in the same manner.”]
Source: https://news.softpedia.com/news/MI5-and-WHO-Websites-Compromised-117291.shtml

