Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 4th, 2011, 18:01 GMT · By Eduard Kovacs

BLOG

XSS Vulnerability Found on AOL Energy Site

SHARE:

Adjust text size:

AOL Energy better fix the problem soon Enlarge picture - AOL Energy better fix the problem soon
Vansh and Vaibhuv, two Indian hackers proved an XSS vulnerability many were talking about on underground forums. They showed that AOL Energy's website, responsible for providing news, analysis and discussions in the electricity sector, presents a serious XSS vulnerability.

The Hacker News revealed that the non-persistent Cross-Site Scripting weakness was claimed by others also, but they got word on it from the Indian duo.

This type of vulnerability, typically found in web applications, can enable an attacker to inject malicious codes into the pages viewed by users. It can also be utilized to bypass access controls, being one of the most common flaws exploited by hackers.

In this situation, we are faced with another somewhat popular website that could be easily used by cybercriminals to serve malware.

TELL US WHAT YOU THINK:

926 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


White Hat Hackers: Barack Obama's Website Vulnerable

Symphony CMS Vulnerable to XSS and SQL Injection Attacks

Malware Hidden in Windows Help Files

NJStar Translation Software Vulnerable to Stack Overflow Attacks

TimThumb Flaw and Blackhole - Recipe for WordPress Hack

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM