Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

June 8th, 2012, 17:51 GMT · By

BLOG

Researchers: Indian Shopping Sites Expose Users by Not Patching XSS Flaws

SHARE:

Adjust text size:


XSS Enlarge picture - XSS
Security researchers from Secfence Technologies have noticed that a lot of Indian online stores contain cross-site scripting (XSS) vulnerabilities, exposing their customers to attacks that rely on social engineering.

The list of websites appointed by the experts as containing the flaws includes: Naaptol (naaptol.com), 100 Bestbuy (100bestbuy.com), WesPro (wespro.phpdevelopment.co.in), and OLX (olx.in).

“If executed cleverly, cyber crooks can cause major damage and make ‘black’ earnings from these vulnerabilities. XSS being at 2nd position at OWASP Top 10 has been neglected in these websites by developers,” Prashant Uniyal, information security analyst at Secfence Technologies, explained.

The researchers have provided screenshots and a proof-of-concept for each of the sites.

“Security of such websites should be beefed up soon. I have tried contacting the concern authority many times, but no response from them. These bugs can be noticed manually by anyone,” Uniyal concluded.
FILED UNDER:
XSS
India
advisory
Secfence

XSS VULNERABILITIES IN VARIOUS INDIAN ONLINE SHOPS - PHOTO GALLERY:

TELL US WHAT YOU THINK:

1,376 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hacker Reports XSS Flaws to US Department of Energy, NASDAQ, NASA

Holy Lulz Crusade: Hackers Target Canadian Government and University Sites

Big Bang Theory Inspires Hacker to Find SQL Injection Flaw on ORNL Site

Hacker Leaks Data from Comcast Site, Protests Against Censorship

Iranian Hackers Compromise NASA SSL Certificate, Agency Investigates

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM