Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

July 13th, 2012, 14:41 GMT · By

BLOG

Persistent XSS Vulnerability Found on Tumblr (Updated)

SHARE:

Adjust text size:


Persistent XSS vulnerability found in Tumblr Enlarge picture - Persistent XSS vulnerability found in Tumblr
Security researcher Riyaz Ahemed Walikar has identified a persistent cross-site scripting (XSS) vulnerability on the popular microblogging platform Tumblr.

XSS flaws are highly common on websites these days, but most of them are non-persistent and implicitly less dangerous.

“XSS can cause a lot of serious problems. An attacker can steal cookies, redirect users to fake or malicious sites, control a user's browser using automated frameworks like BeEF and download and execute exploits on the victim's computer,” Walikar explained.

“Stored XSS is even more dangerous since the script is stored on the server and is executed everytime user visits an infected page.”

According to the expert, Tumblr were notified more than three weeks ago on the issue, but so far the website's representatives have failed to address it. Walikar says that he will publish more technical details on the security hole in the upcoming period.

Update. Walikar has told Softpedia that the persistent XSS vulnerability has been addressed by Tumblr. The technical details are available on his blog.

TELL US WHAT YOU THINK:

1,608 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


IP.Board 3.3.4 Released, XSS Vulnerability Addressed

The Jester Presents Project Looking Glass, Warns “Bad Guys”

WhiteHat: XSS Most Prevalent Site Vulnerability in 2011

Menshn Co-Founder Says Site Is Secure, Experts Try to Prove Him Wrong

Western Australian Auditor General: Organizations Can’t Identify Cyber Attacks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM