Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

March 4th, 2013, 20:41 GMT · By

BLOG

Apple Fixes DOM XSS Vulnerability on “Find Locations” Website

SHARE:

Adjust text size:


DOM-based XSS on Apple website Enlarge picture - DOM-based XSS on Apple website
Independent security researcher Mirza Burhan Baig of blackbitz.net has identified a DOM-based cross-site scripting (XSS) vulnerability on the “Find Locations” subdomain of Apple’s official website (locate.apple.com). 

Apple has addressed the issue and officially credited the expert for his findings.

The researcher has explained that the DOM-based XSS vulnerability could have been triggered on all the approximately 85 webpages dedicated to finding sales, service, training and certification, and consulting locations around the world.

The expert says the vulnerability, which he identified and reported back in December, could have been used to hijack user sessions and possibly even accounts.

You can check out the proof-of-concept screenshot sent by the researcher to Softpedia.

Back in December 2012, Mirza Burhan Baig identified a similar DOM-based XSS vulnerability on Microsoft’s Surface website.

TELL US WHAT YOU THINK:

1,341 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


XSS Vulnerabilities Fixed in Apache HTTP Server 2.4.4

Directory Traversal and XSS Vulnerabilities Found in Avira’s BetaCenter (Updated)

Two DOM-Based XSS Vulnerabilities Addressed by Booking.com

7 Vulnerabilities Identified on Mega in First Week of Rewards Program

eBay Fixes XSS Vulnerability on Careers Website

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM