Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 28th, 2011, 13:46 GMT · By Eduard Kovacs

BLOG

ArcaVit Antivirus Website Vulnerable to XSS and Iframe Injection Attacks

SHARE:

Adjust text size:

ArcaBit's Polish website is vulnerable to an XSS attack Enlarge picture - ArcaBit's Polish website is vulnerable to an XSS attack
The product checkout page of ArcaBit’s Polish website presented vulnerabilities that could have allowed a hacker to execute a maliciously crafted arbitrary code.

Team Elite reports that two years ago the website had the same weaknesses, but after a redesign process, the site became once again vulnerable to cross-site scripting and iframe injection attacks.

XSS issues are considered to be the most common in websites, but it’s ironic when we find them on the page of a company that claims “security is their priority.”

ArcaBit is actually the website of the vendor that develops the ArcaVit antivirus solution, a product created by “high class experts, designers, programmers and implementation specialists, but also passionates.”

The issue was resolved one day after the disclosure, but it's highly unfortunate when someone is too busy with the more complex matters and they forget to take care of the simple things.

TELL US WHAT YOU THINK:

901 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


XSS Vulnerability Found in White House Website

Rails 3.1.2 Fixes XSS Vulnerability

Injector Hackers Reveal XSS Vulnerability on myOpenID

XSS Vulnerability Found on AOL Energy Site

Indian Hacker Finds Vulnerability in Speed Bit Search Engine

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM