Version: 2008
home
reviews
news
downloads
cnet tv
HOLIDAY HELP DESK:
Broadcasting live at 1:00 p.m., PT
log in
join CNET
welcome,
my profile
log out
Home
Reviews
News
Downloads
CNET TV
iPhone 3GS from AT&T. Free Shipping
Ultimate Holiday Tech Guide
Content from CNET tagged with
XSS
[x]
,
security
[x]
Show Results by
Show All
Reviews
(1)
News
(15)
Narrow Your Results
flaw
(9)
attack
(8)
e-mail
(6)
Google Inc.
(6)
Web browser
(5)
attacker
(5)
Microsoft Corp.
(4)
vulnerability
(4)
MySpace
(3)
PC
(3)
phishing
(3)
Gmail
(3)
JavaScript
(3)
Web application
(2)
link
(2)
News Stories
Showing
1-15
of
15
results found
Gmail cookie vulnerability exposes user's privacy
September 27, 2007
Program developed by "ethical hacking" group takes advantage of cross-site scripting vulnerability to steal contacts, forward e-mail.
TAGS:
Gmail
,
XSS
,
cookie
,
vulnerability
,
organization
,
attacker
,
hacking
,
Google Inc.
,
password
,
security
,
e-mail
Yahoo fixes Web mail security flaw
October 22, 2005
The flaw, now fixed, opened the door to phishing scams, account hijacks and other attacks, but Yahoo said no user attacks were reported.
TAGS:
flaw
,
Yahoo! Inc.
,
security flaw
,
phishing
,
XSS
,
attack
,
security
Google fixes Web site security bug
October 10, 2005
Vulnerability could have exposed some users to account hijacks, phishing scams and other attacks, security firm says.
TAGS:
Finjan Software Inc.
,
XSS
,
flaw
,
phishing
,
attacker
,
Google Inc.
,
Gmail
,
bug
,
security
,
attack
,
Microsoft Corp.
,
e-mail
The security risk in Web 2.0
July 28, 2006
Security has become a no-brainer for desktop software, but the same doesn't hold true for the booming world of Web applications.
TAGS:
AJAX
,
Web 2.0
,
XSS
,
Web application
,
desktop software
,
expert
,
Time Warner Inc.
,
security
,
JavaScript
,
programming
,
house
,
MySpace
,
Yahoo! Inc.
,
Google Inc.
Symantec warns of router compromise
January 24, 2008
Security company says it has seen an attack using a cross-site scripting flaw in 2Wire DNS routers.
TAGS:
Symantec Corp.
,
e-card
,
2Wire
,
XSS
,
router
,
attack
,
DNS
,
domain name
,
HTTP
,
IP address
,
security
,
IP
Samy opens new front in worm war
October 17, 2005
Security experts fear would-be attackers will copy the worm, which exploits an unaddressed scripting flaw.
TAGS:
XSS
,
Trend Micro Inc.
,
worm
,
MySpace
,
front
,
profile
,
denial of service
,
attack
,
Web browser
,
security
,
e-mail
Google plugs account hijack holes
January 16, 2007
If left unpatched, the vulnerability could let hackers modify third-party documents and view e-mail subjects, search history.
TAGS:
XSS
,
Google Inc.
,
vulnerability
,
hacker
,
cookie
,
security
,
e-mail
Mozilla issues security updates
December 20, 2006
"Critical" updates cover flaws in Firefox, Thunderbird and SeaMonkey that could allow for cross-site scripting and remote execution of code.
TAGS:
Mozilla Corp.
,
security update
,
Mozilla Thunderbird
,
flaw
,
XSS
,
Firefox
,
security
Acrobat flaw could spawn Web attacks
January 4, 2007
Vulnerability in ubiquitous Acrobat Reader software could be a boon for cybercrooks and spark a rise in Web-based attacks, experts warn.
TAGS:
iDefense
,
XSS
,
Adobe Acrobat
,
VeriSign Inc.
,
Adobe Acrobat Reader
,
Adobe Systems Inc.
,
attack
,
Symantec Corp.
,
Adobe PDF
,
flaw
,
security
,
link
,
Web browser
Firefox, IE vulnerable to fake login pages?
November 22, 2006
Flaw could enable attackers to compromise usernames and passwords, security researcher warns, citing exploit on MySpace.
TAGS:
XSS
,
MySpace
,
username
,
Firefox
,
exploit
,
attacker
,
flaw
,
Firefox 2.0
,
attack
,
password
,
Mozilla Corp.
,
security
,
blog
,
Microsoft Internet Explorer
,
server
,
Web browser
Google plugs 'obscure' phishing holes
December 21, 2005
Web site security flaws could have enabled phishing scams, account hijacks and other attacks.
TAGS:
Watchfire
,
phishing
,
flaw
,
XSS
,
Google Inc.
,
attacker
,
security company
,
Gmail
,
security
,
attack
,
Microsoft Corp.
,
e-mail
Serious flaw in Google Desktop gets fix
February 21, 2007
Google plugs security holes in popular desktop search software that could open up data on a PC to intruders.
TAGS:
Watchfire
,
Google Desktop
,
Google Inc.
,
XSS
,
vulnerability
,
flaw
,
security company
,
attack
,
security
,
PC
,
link
JavaScript bug-hunting tool demonstrated
March 24, 2007
Security researcher says his company won't let him release Jikto, which turns PCs of unknowing Web surfers into crawlers.
TAGS:
SPI Dynamics
,
JavaScript
,
Web security
,
researcher
,
XSS
,
security
,
Web browser
,
PC
MSN flaw put Hotmail accounts at risk
June 7, 2005
Microsoft takes part of its MSN site offline after learning of a flaw that could be used to gain access to the free e-mail service.
TAGS:
MSN Hotmail
,
MSN
,
flaw
,
XSS
,
MSN Messenger
,
Microsoft Corp.
,
security
,
e-mail
Tool turns unsuspecting surfers into hacking help
March 21, 2007
With Jikto, JavaScript on a Web site can turn PCs into a bug-hunting tool, thus doing a hacker's dirty work.
TAGS:
Web security
,
JavaScript
,
attacker
,
Web surfer
,
SQL injection
,
hacking
,
XSS
,
hacker
,
creator
,
Web application
,
flaw
,
bot
,
vulnerability
,
SQL
,
researcher
,
security
Sponsored matches for
"security"
My Lists
My software updates
log in
|
join CNET