Version: 2008
  • On mySimon: Pea Coats Are Another Wardrobe Staple
advertisement
Content from CNET tagged with

XSS

News Stories

Showing 1-17 of 17 results found

Gmail cookie vulnerability exposes user's privacy

September 27, 2007 Program developed by "ethical hacking" group takes advantage of cross-site scripting vulnerability to steal contacts, forward e-mail. TAGS: Gmail, XSS, cookie, organization, vulnerability, attacker, hacking, Google Inc., security, password, e-mail

Yahoo fixes Web mail security flaw

October 22, 2005 The flaw, now fixed, opened the door to phishing scams, account hijacks and other attacks, but Yahoo said no user attacks were reported. TAGS: Yahoo! Inc., security flaw, flaw, phishing, XSS, attack, security

The security risk in Web 2.0

July 28, 2006 Security has become a no-brainer for desktop software, but the same doesn't hold true for the booming world of Web applications. TAGS: AJAX, XSS, Web 2.0, Web application, desktop software, expert, Time Warner Inc., MySpace, JavaScript, security, house, programming, Yahoo! Inc., Google Inc.

Samy opens new front in worm war

October 17, 2005 Security experts fear would-be attackers will copy the worm, which exploits an unaddressed scripting flaw. TAGS: XSS, Trend Micro Inc., worm, MySpace, front, profile, denial of service, attack, Web browser, security, e-mail

Google fixes Web site security bug

October 10, 2005 Vulnerability could have exposed some users to account hijacks, phishing scams and other attacks, security firm says. TAGS: Finjan Software Inc., XSS, phishing, flaw, attacker, Google Inc., bug, Gmail, security, attack, Microsoft Corp., e-mail

Symantec warns of router compromise

January 24, 2008 Security company says it has seen an attack using a cross-site scripting flaw in 2Wire DNS routers. TAGS: Symantec Corp., e-card, 2Wire, XSS, router, attack, domain name, DNS, HTTP, IP address, security, IP

Google plugs account hijack holes

January 16, 2007 If left unpatched, the vulnerability could let hackers modify third-party documents and view e-mail subjects, search history. TAGS: XSS, Google Inc., vulnerability, hacker, cookie, security, e-mail

A phishing wolf in sheep's clothing

March 14, 2005 Scammers are increasingly injecting their own code into legitimate Web page URLs--a threat that could spell trouble for online banks. TAGS: XSS, phishing, bank, criminal, target, attack, server, e-mail

Acrobat flaw could spawn Web attacks

January 4, 2007 Vulnerability in ubiquitous Acrobat Reader software could be a boon for cybercrooks and spark a rise in Web-based attacks, experts warn. TAGS: iDefense, Adobe Acrobat, XSS, VeriSign Inc., Adobe Acrobat Reader, Adobe Systems Inc., attack, Adobe PDF, Symantec Corp., flaw, link, security, Web browser

Firefox, IE vulnerable to fake login pages?

November 22, 2006 Flaw could enable attackers to compromise usernames and passwords, security researcher warns, citing exploit on MySpace. TAGS: XSS, MySpace, username, Firefox, attacker, exploit, flaw, Firefox 2.0, attack, password, Mozilla Corp., security, blog, Microsoft Internet Explorer, server, Web browser

Serious flaw in Google Desktop gets fix

February 21, 2007 Google plugs security holes in popular desktop search software that could open up data on a PC to intruders. TAGS: Watchfire, Google Desktop, Google Inc., XSS, vulnerability, flaw, security company, attack, security, PC, link

Mozilla issues security updates

December 20, 2006 "Critical" updates cover flaws in Firefox, Thunderbird and SeaMonkey that could allow for cross-site scripting and remote execution of code. TAGS: Mozilla Corp., security update, Mozilla Thunderbird, flaw, XSS, Firefox, security

MSN flaw put Hotmail accounts at risk

June 7, 2005 Microsoft takes part of its MSN site offline after learning of a flaw that could be used to gain access to the free e-mail service. TAGS: MSN Hotmail, MSN, flaw, XSS, MSN Messenger, Microsoft Corp., security, e-mail

Google plugs 'obscure' phishing holes

December 21, 2005 Web site security flaws could have enabled phishing scams, account hijacks and other attacks. TAGS: Watchfire, phishing, flaw, XSS, Google Inc., security company, attacker, Gmail, security, attack, e-mail, Microsoft Corp.

Phishing--who's taking the bait now?

November 23, 2004 Kavado CEO Vikram Desai says blended phishing is likely to sucker more users into divulging valuable information. TAGS: phishing, e-business, victim, XSS, bank, Web browser, e-mail, link

Tool turns unsuspecting surfers into hacking help

March 21, 2007 With Jikto, JavaScript on a Web site can turn PCs into a bug-hunting tool, thus doing a hacker's dirty work. TAGS: Web security, JavaScript, attacker, Web surfer, hacking, SQL injection, creator, XSS, hacker, Web application, bot, flaw, vulnerability, SQL, researcher, security

JavaScript bug-hunting tool demonstrated

March 24, 2007 Security researcher says his company won't let him release Jikto, which turns PCs of unknowing Web surfers into crawlers. TAGS: SPI Dynamics, JavaScript, Web security, researcher, XSS, security, Web browser, PC
Sponsored matches for "XSS"