Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

December 18th, 2011, 15:46 GMT · By Eduard Kovacs

BLOG

Kaspersky Store Presents XSS and Iframe Injection Vulnerability

SHARE:

Adjust text size:

Kaspersky Poland vulnerable Enlarge picture - Kaspersky Poland vulnerable
Team Elite has published a proof of concept to show a cross-site scripting (XSS) and an iframe injection flaw in Kaspersky’s Polish product store (softbuy.pl/kaspersky/store).

It seems that the product purchase page contains some weaknesses which could allow a hacker to execute arbitrary code.

It’s not uncommon for these vulnerabilities to be taken advantage of by hackers and that’s why it’s always recommended to make sure the holes are quickly patched up when they’re discovered.

I have contacted Kaspersky to see if anything has been done so far to resolve the situation. As always, they’ll probably reply in the shortest time, so stay tuned to find out how the flaws are handled.

Not long ago, hackers attacked what they believed to be one of Kaspersky’s sites, but at the time they ended up defacing a website set up by cybersquatters to attract unsuspecting users who may fall for their cleverly planned schemes.
FILED UNDER:
Kaspersky
iframe
XSS

TELL US WHAT YOU THINK:

2,001 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Adobe Releases Hotfix for ColdFusion XSS Flaw

XSS Vulnerability Found in Google Code

Mobile Apps That Embed Browsers Vulnerable to XSS Attacks

XSS Vulnerability Found in White House Website

Rails 3.1.2 Fixes XSS Vulnerability

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM