Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

October 31st, 2012, 19:41 GMT · By

BLOG

Persistent XSS and SQL Injection Flaws on ESET Taiwan Website Fixed

SHARE:

Adjust text size:


XSS and SQL Injection vulnerabilities fixed on the site of ESET Taiwan Enlarge picture - XSS and SQL Injection vulnerabilities fixed on the site of ESET Taiwan
Security researcher Rafay Baloch has identified a persistent cross-site scripting (XSS) vulnerability and an SQL Injection flaw on the official website of ESET Taiwan (eset.tw).

“The search box is vulnerable. Once the user inserts an inverted comma into the box, the alert is executed. This, at first, looked like a self XSS, however it can be exploited by using clickjacking techniques, since X-frame header is not set, making the page render in an IFRAME,” the expert told Softpedia when he uncovered the issues.

The SQL Injection, on the other hand, could have been exploited by a remote attacker to gain access to the site’s databases.

For his findings and for practicing responsible disclosure, ESET Security team officially thanked him and provided the researcher with a license for ESET Smart Security.

“Your information has helped us and our partner responsible for the site to improve security of online services and has prevented malicious exploitation of these vulnerabilities,” ESET representatives told Baloch.

Check out the proof-of-concept pictures below.

VULNERABILITIES IN ESET TAIWAN WEBSITE - PHOTO GALLERY:

TELL US WHAT YOU THINK:

1,616 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


US Government and Military Sites Hacked by NullCrew, Thousands of Credentials Leaked

Q3, 2012 Report: XSS Named the Most Common Attack Type in Europe and US

Sites of Indian Mobile Operators Idea, Tata and BSNL Contain Serious Vulnerabilities

XSS Flaws Found in BigBang, AirWP, ZigZag and Convergence WordPress Themes

Persistent XSS Flaws on TopCoder.com Allow Hackers to Lower Ranks of Members (Updated)

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM