Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 7th, 2013, 09:51 GMT · By

BLOG

AOL Shopping Website Plagued by XSS and iFrame Injection Vulnerabilities

SHARE:

Adjust text size:


iFrame Injection vulnerability in AOL Shopping Enlarge picture - iFrame Injection vulnerability in AOL Shopping
Indian Security researcher Deepanker Verma claims to have uncovered cross-site scripting (XSS) and iFrame injection vulnerabilities on the shopping website of AOL.

According to the expert, cybercriminals could leverage these flaws to steal user cookies and hijack sessions.

To demonstrate the fact that iFrames can be injected into the AOL Shopping website, Verma has added an iFrame that points to his own site (see screenshot).

“This is a popular shopping website with millions of users. An attacker can trick innocent users and use this vulnerability for malicious task,” the researcher wrote on Hacking Tricks.

The expert says that the vulnerabilities have been reported to AOL, but so far they haven’t responded to his notifications.

Previously, Deepanker Verma has identified security holes in websites such as Pinterest, the Indian search engine Guruji, and Google Books.

Update. According to security researcher Suriya Prakash, AOL doesn't handle vulnerability reports too well.

He says that the company still hasn't addressed the XSS issues he reported to them a few months ago. 

Moreover, it turns out that a security hole similar to the one identified by Verma was found by the TeamHav0k hacker group almost one year ago.

TELL US WHAT YOU THINK:

1,261 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


XSS Vulnerability in HostGator India Affects over One Million Websites

Zynga Fixes XSS and SQL Injection Vulnerabilities on “With Friends” Website

XSS and Cookie Handling Vulnerabilities Identified on HTC Website

Researcher Finds XSS Vulnerabilities in cPanel & WHM 11.34 – Video

Microsoft Fixes DOM XSS Flaw in Surface Domain After Being Notified by Expert

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM