XSS Everywhere – Another Full Disclosure Run
July 19th, 2006 by SecuriTeam, Filed under: Commentary, Full Disclosure, Web
much like before with dcrab, another security researcher decided to prove to the world what everyone knows and ignores – almost every web site has vulnerabilities and these are being ignored.
skyout just released a list of sites which are affected by xss, in full disclosure mode:
http://web3.m34s11.vlinux.de/xss_research.htm
among the sites are americanexpress.com, walmartstores.com, pcworld.co.uk, weather.com, netscape.com, thestreet.com and others. we are working to notify them and hopefully prevent some phishing. but once something is out there, it’s out there. full disclosure.
i expect we will start seeing such lists quite regularly, after all, these are everywhere.
gadi evron,
ge@beyondsecurity.com.




Pingback: Financial Thoughts