funsec mailing list archives

These days of several XSS vulns on known sites


From: Juha-Matti Laurio <juha-matti.laurio () netti fi>
Date: Tue, 6 Nov 2007 23:53:33 +0200 (EET)

The role and seriousness of cross-site scripting (XSS) vulnerabilities has been a subject of recent Full-Disclosure 
discussion.

The fact is, however, that since Saturday You can simply pick the following widely known targets of XSS:
bankofamerica.com, cnn.com, fbi.gov, symantec.com, apple.com etc.

I have collected more than 10 reports about well-known Web sites suffering about XSS issues.
According to the source Xssed.com most of them are still unpatched.

Link to the SecuriTeam Blogs post:
http://blogs.securiteam.com/?p=1030

- Juha-Matti
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: