Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

April 12th, 2012, 08:42 GMT · By

BLOG

XSS and SQL Injection Vulnerabilities Identified on Yahoo! Sites

SHARE:

Adjust text size:


XSS on Yahoo! subdomain Enlarge picture - XSS on Yahoo! subdomain
This week, security researchers have focused their attention on websites owned by Yahoo! and found that some of them contain serious vulnerabilities.

First, the security expert known as flexxpoint identified cross-site (XSS) scripting flaws on three different Yahoo subdomains.

“One of these subdomains have a very "strong" filter:<script> is blocked ...but no surprise <ScRipT> is allowed,” flexxpoint wrote on his blog.

One day later, Georgian security researcher Ucha Gobejishvili found an SQL Injection vulnerability on a “Yahoo Customers Website.”

According to Gobejishvili, the remotely exploitable security hole can be leveraged by an attacker to execute his own SLQ commands to compromise the site’s database management system and gain access to all the data.

The Georgian also posted proof of the fact that Yahoo representatives are already working on addressing the issues he discovered.

It’s uncertain if flexxpoint contacted Yahoo on this occasion, but he usually notifies the affected vendor when finding such serious vulnerabilities.

Note. My Twitter account has been erroneously suspended. While this is sorted out, you can contact me via my author profile or follow me at @EduardKovacs1

VULNERABILITIES ON YAHOO SITES - PHOTO GALLERY:

TELL US WHAT YOU THINK:

1,406 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hackers Expose XSS Flaws in Vatican, Humboldt and NASA Sites

Hacker Confronts Microsoft on Lack of XSS Filters in MSN Explorer (Exclusive, Updated)

Joomla 2.5.4 Released, Low Priority Vulnerabilities Fixed

Hacker Reports Flaw in E-Learning Site Edmodo (Exclusive)

SQL Injection Vulnerabilities Fixed in MyBB 1.6.7

READER COMMENTS:


Comment #1 by: Wide Glide on 29 Nov 2012, 08:36 UTC reply to this comment

http://forums.malwarebytes.org/index.php?showtopic=118764&pid=618168&st=0&#entry618168

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM