iEntry 10th Anniversary RSS Newsletter Advertising
Visit Twellow.com

Google Crosses Out Cross-Site Scripting Issue

Post to Twitter Post to Facebook

The Internet security firm Finjan and its Malicious Code Research Center provided Google with information leading to the correction of two vulnerabilities.

Cross-site scripting has plagued users of the Internet Explorer and Firefox browsers. Malicious web pages exploiting cross-site scripting vulnerabilities have driven Microsoft and Mozilla to patch their browsers several times. Finjan told Google in September that two of its subdomain sites that utilized forms containing similar vulnerabilities.

The forms in question did not do data validation or filtering, Finjan has stated in a press release, and could have allows for code injection that could steal another user's 'cookie' file. With that cookie, someone could access the victim's account, and even possibly alter the contents of the web page.

In the statement, Limor Elbaz, Vice President of Business Development and Strategy with Finjan explained, "The cross site scripting vulnerability could have allowed a remote attacker to take over victims' Google Accounts, or fake the website's content in order to deceive end users into downloading malicious content or providing personal and confidential information (known as 'phishing')."

Google has since addressed the problem and corrected the forms. Finjan noted that the sites in question no longer have the cross-site scripting vulnerability.

David Utter is a staff writer for WebProNews covering technology and business. Email him here.

News Tags: Google

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
3 + 4 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.
Featured Headline
Search Bing From Hotmail Inbox to Insert Content
Bing Added to Quick Add Feature
1 comment | 22 hours ago
WebProNews on Facebook
 
Subscribe to WebProNews


Send me relevant info