Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 27th, 2012, 08:05 GMT · By Eduard Kovacs

XSS Vulnerability Found in Google, Forbes, Myspace, MTV and Ferrari

SHARE:

Adjust text size:


XSS security flaw found in Google Apps
Enlarge picture
A researcher from the Vulnerability Laboratory came across a cross-site scripting (XSS) vulnerability in the Google Apps webpage, hosted on the google.com domain, but also in other popular websites.

Ucha Gobejishvili, also known as longrifle0x, found the flaw in Google Apps and reported it to Google.

Even though the risk level is estimated as low, if unresolved, the security hole present in one of the search modules could allow a remote attacker to hijack cookies and even steal accounts.

On the other hand, the attacker would have to social engineer the victim into performing certain tasks for the session hijacking to be successful.

Ferrari's online store contains an XSS vulnerability
Enlarge picture
The vulnerability had been reported on January 21 and the vendor responded on January 23, but at the time of writing the bug still exists on the Google page.

This is not the only vulnerability found by longrifle0x in the past days. The Forbes search page, Ferrari’s official online store, MTV, and the social network MySpace also contain the same type of vulnerability. Unfortunately, none of them is currently patched up and reports from XSSED reveal that the domains were already XSS’ed.

Last year the same security expert found XSS in Opera, Sony Ericsson and the official site of sportswear provider Puma.

XSS vulnerabilities are very common in commercial websites. A few days ago, hackers from TeamHav0k found such bugs in other high-profile websites such as the ones belonging to Rochester Institute of Technology, Arizona State University, NYU Poly’s Center for Advanced Technology in Telecommunications, Michigan State University and Aurora University,

Beside university sites, the hackers also found the same security flaws in major US government sites.

A day before revealing this, TeamHav0k found cross-site scripting bugs in sites that belong to Verizon, Huffington Post, European Organization for Nuclear Research (CERN) , Electronic Arts (EA), IGN and New York Times.

TELL US WHAT YOU THINK:

3,305 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hacker Finds SQL Injection Vulnerability in NATO Website

TeamHav0k’s OP XSS: Vulnerabilities in US Government Sites (Exclusive)

Hackers Prove EA, IGN, ImageShack, NY Times, Verizon Vulnerable

XSS Attacks Possible due to IE URI Encoding Flaw

WordPress 3.3.1 Released to Fix XSS Vulnerability

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM