Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

December 8th, 2011, 07:40 GMT · By Eduard Kovacs

BLOG

XSS Vulnerability Found in Google Code

SHARE:

Adjust text size:

An XSS vulnerability was found in Google Code's Code Playground Enlarge picture - An XSS vulnerability was found in Google Code's Code Playground
A hacker called Vansh Sharma claims he found a cross-site scripting (XSS) vulnerability in Google Code’s Code Playground, the section of Google Code where users can test their programming skills.

The Hacker News published a proof of concept that can be tried out by anyone. Just go to http://code.google.com/apis/ajax/playground/ and replace one of the present codes with <img src="<img src=search"/onerror=alert("XSS")//">. In order to edit the code you need to first press the Edit HTML button.

Once the code is inserted, click on Debug Code. You will be presented with an error message alerting you that the “Sample must have <head> element”. Press the OK button and wait for a popup which says “XSS”.

If at first it doesn’t work, you can try again, but instead of pressing Debug Code, click on Run Code.
FILED UNDER:
XSS
Google
code
vulnerability

TELL US WHAT YOU THINK:

796 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Mobile Apps That Embed Browsers Vulnerable to XSS Attacks

15-Year-Old Finds XSS Vulnerability on Twitter

Nigerian Ministry Website Vulnerable to iFrame Injection and XSS Attacks

Rails 3.1.2 Fixes XSS Vulnerability

Injector Hackers Reveal XSS Vulnerability on myOpenID

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM