Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

February 1st, 2012, 15:23 GMT · By Eduard Kovacs

BLOG

Researcher Finds XSS Flaws in Java, Nero and Sun Websites

SHARE:

Adjust text size:

An XSS attack using these flaws is not mitigated by Firefox 10 Enlarge picture - An XSS attack using these flaws is not mitigated by Firefox 10
Security researcher Ucha Gobejishvili, also known as longrifle0x, found cross-site scripting (XSS) vulnerabilities in another series of important websites, including java.com, developers.sun.com, java.sun.com, and nero.com.

The expert’s findings were submitted to XSSed, a site that provides information on XSS attacks, on January 27 and they were disclosed a couple of days later, but at the time of writing the issues remain unresolved.

On the bright side of things, potential attacks using these flaws work only on users who rely on Mozilla Firefox browsers, including the recently released Firefox 10. The later variants of Internet Explorer and Google Chrome are designed to mitigate such attacks.

Unfortunately, there are plenty of Firefox customers that may be targeted by cybercriminals who could use these security holes to launch their attacks.

Hopefully, the involved companies will act on patching up the affected domains to make sure their visitors are protected.
FILED UNDER:
XSS
Nero
Sun
Java
vulnerability

TELL US WHAT YOU THINK:

806 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Security Vulnerabilities Fixed in FAA.Gov and Oracle Solutions

XSS Vulnerability Found in Google, Forbes, Myspace, MTV and Ferrari

Hacker Finds SQL Injection Vulnerability in NATO Website

TeamHav0k’s OP XSS: Vulnerabilities in US Government Sites (Exclusive)

Hackers Prove EA, IGN, ImageShack, NY Times, Verizon Vulnerable

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM