Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 28th, 2012, 13:46 GMT · By

BLOG

XSS and Cookie Handling Vulnerabilities Identified on HTC Website

SHARE:

Adjust text size:


XSS in HTC website Enlarge picture - XSS in HTC website
16-year-old security researcher Thamatam Deepak has identified a number of three cross-site scripting (XSS) vulnerabilities and a cookie handling flaw on the website of world-renowned smartphone manufacturer HTC.

The expert told The Hacker News that the vulnerabilities – which affected pages such as product security, account information, and smartphone presentation – have been addressed by HTC after he notified them.

If unfixed, the XSS vulnerabilities could have been leveraged by a remote attacker to inject arbitrary content, while the cookie handling flaw might have been exploited to hijack user accounts.

This isn’t the first time when security experts find XSS bugs on HTC’s website. Back in April, researcher Shadab Siddiqui identified similar flaws and reported them to the company.

However, at the time, they failed to respond to his notifications and the vulnerabilities remained unfixed for months.

TELL US WHAT YOU THINK:

1,631 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Researcher Finds XSS Vulnerabilities in cPanel & WHM 11.34 – Video

Microsoft Fixes DOM XSS Flaw in Surface Domain After Being Notified by Expert

Egyptian Hacker Claims to Have Breached Yahoo! Servers

Hotmail Accounts Can Be Hijacked by Stealing Authentication Cookies – Video

PayPal Rewards Researcher with $5,000 for Finding Remote Code Execution Flaw

READER COMMENTS:


Comment #1 by: phydroxide on 04 Jan 2013, 21:52 UTC reply to this comment

Kinda gives you an idea how loosely the term "Security Researcher" is used. I find this to be unfortunate.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM