Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 23rd, 2013, 21:11 GMT · By

BLOG

Microsoft Addresses XSS Vulnerability on Delish

SHARE:

Adjust text size:


XSS vulnerability on Delish.com Enlarge picture - XSS vulnerability on Delish.com
Security researcher Deepanker Verma has identified a cross-site scripting vulnerability in the main search form of Delish, the popular cooking website operated by Microsoft and Hearst Magazines. The security hole has been fixed.

The expert, who is the founder of the Hacking Tricks website, has told me in an email that he reported the vulnerability to Microsoft back on January 11.

The company acknowledged the existence of the security hole and promised to fix it shortly after that.

“Today [January 23] they patched the vulnerability. Microsoft also asked for my name and website URL to put on the acknowledgement page,” the researcher said.

Earlier this month, Verma identified XSS and iFrame injection vulnerabilities on AOL’s Shopping website. However, AOL has failed to respond to his inquiries, leaving the site vulnerable to cyberattacks.

TELL US WHAT YOU THINK:

1,276 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Expert Claims to Have Identified Persistent XSS Flaw in Google’s Blogger Service

Drupal 7.19 and 6.28 Released to Address XSS, Access Bypass Flaws

Expert Finds Security Holes in Sites of Microsoft, Twilio and ProActive CMS

Yahoo! Users’ Accounts Still Not Safe, DOM XSS Not Properly Fixed – Video (Updated)

AOL Shopping Website Plagued by XSS and iFrame Injection Vulnerabilities

READER COMMENTS:


Comment #1 by: Chetan on 23 Jan 2013, 22:59 UTC reply to this comment

Great Job Mr Verma

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM