Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 28th, 2011, 07:54 GMT · By Eduard Kovacs

BLOG

Nepal Communications Ministry Vulnerable to XSS and Iframe Injection

SHARE:

Adjust text size:

Nepal Information and Communications Ministry vulnerable to cross-site scripting attack Enlarge picture - Nepal Information and Communications Ministry vulnerable to cross-site scripting attack
The official website belonging to the Information and Communications Ministry of Nepal was discovered as presenting two major vulnerabilities that could allow a hacker to run a piece of arbitrary code.

Team Elite, the ones that discovered the cross-site scripting and iframe injection flaws, already notified the institution to make sure the holes are patched up as soon as possible.

The weak section is actually the contact page. The form it contains can be filled with strings that represent a script or an iframe, which could permit an attacker to execute his own malicious code.

The disclosure was made on November 27, but at the time of writing the vulnerability remains present. Hopefully, the website’s administrators will act quickly on resolving the issue to avoid any unfortunate situations.
FILED UNDER:
XSS
iframe
Nepal

TELL US WHAT YOU THINK:

731 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


XSS Vulnerability Found in White House Website

Injector Hackers Reveal XSS Vulnerability on myOpenID

Rails 3.1.2 Fixes XSS Vulnerability

XSS Vulnerability Found on AOL Energy Site

Symphony CMS Vulnerable to XSS and SQL Injection Attacks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM