Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

February 7th, 2012, 08:55 GMT · By Eduard Kovacs

BLOG

Electronic Arts Fixes XSS Vulnerability on Public Website

SHARE:

Adjust text size:

EA fixes XSS flaw in official website Enlarge picture - EA fixes XSS flaw in official website
Sebastian Lodtke, a researcher from the Vulnerability Lab, identified a cross-site scripting (XSS) vulnerability in the public website of the American video game developer, marketer, and publisher Electronic Arts (EA).

The non-persistent security hole could have allowed a remote attacker to hijack customer sessions with the aid of some social engineering techniques.

Successful exploitation of this weakness may have resulted not only in session hijacking, but also in client side phishing and even account theft.

EA was first notified of the issues just before Christmas in 2011 and then again on two other occasions. Sometime between February 2 and February 6, 2012, the vendor responded and patched up the flaws.

It appears that EA is having a hard time keeping its online assets secure, last week hackers managing to breach and deface their official forum.
FILED UNDER:
vulnerability
XSS
EA

TELL US WHAT YOU THINK:

662 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Official EA Forum Hacked and Defaced, Data Is Secure

XSS Vulnerability Found in Google, Forbes, Myspace, MTV and Ferrari

Researcher Finds XSS Flaws in Java, Nero and Sun Websites

Security Vulnerabilities Fixed in FAA.Gov and Oracle Solutions

Hackers Prove EA, IGN, ImageShack, NY Times, Verizon Vulnerable

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM