Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

December 19th, 2011, 10:13 GMT · By Eduard Kovacs

BLOG

Avast and Norman Websites Found Vulnerable to XSS Attacks

SHARE:

Adjust text size:

Avast website susceptible to XSS attack Enlarge picture - Avast website susceptible to XSS attack
We’re presented with another situation in which security solutions providers fail to protect their public assets, leaving them vulnerable for cyberattacks.

The official site of Norman (norman.com), a proactive content security solutions and forensics malware tools provider, and the Polish variant of Avast’s website (lers.pl) were found to contain serious XSS flaws.

Team Elite is responsible for finding and disclosing the vulnerabilities, which if not fixed, could give a hacker an easy opportunity to execute arbitrary code.

In the case of Norman, the installation key retrieval page is vulnerable while on Avast’s website, the product purchase page contains an XSS and an iframe injection hole.

Team Elite states that they always inform the website’s owner when they discover a vulnerability, but many of them seem to act very slowly, in most cases silently fixing the flaws.

TELL US WHAT YOU THINK:

749 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Kaspersky Store Presents XSS and Iframe Injection Vulnerability

Adobe Releases Hotfix for ColdFusion XSS Flaw

City of Boston Website Hacked, Administrator Passwords Leaked

City of Glendale Website Flaws Revealed by TeamDX (Exclusive, Updated)

XSS Vulnerability Found in Google Code

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM