flaws cross-site scripting
Outsmarting Tomorrow's Hackers Today
White Paper Network IDS/IPS and first-generation Web Application Firewalls (WAFs) don't protect against today's sophisticated web application threats, such as cross-site scripting, injection... [01 Oct 2009]
Apple goes on a security Safari with browser patches
News Independent security vendor Secunia gave the flaws addressed by the update a "highly critical" ranking. Both of the flaws affect WebKit, the open source layout engine used in Safari. Apple has released... [09 Jul 2009]
iPhone 3.0 patches 46 security holes
News The 46 flaws could allow an attacker to bypass security restrictions, shut down an application, disclose sensitive information, conduct cross-site scripting and... [19 Jun 2009]
Does open source pose a security risk?
News Independent software vendors (ISVs) selling proprietary software have claimed the open-source development process exposes open-source software to greater security risks, while open-source developers argue that the openness of the process... [22 Jul 2008]
Google open sources web 2.0 security
News Google has released as open source a web application assessment tool, Ratproxy, that is designed to root out potential security flaws. The tool has been used at Google for unearthing problems such as... [14 Jul 2008]
Holes found in Google Desktop
News Several flaws in the popular Google Desktop software could open PCs up to intruders and possible data theft, a security company has warned. One of the problems is a cross-site... [22 Feb 2007]
Alert over Adobe Acrobat flaw
News Such attacks in the past relied on flaws in websites but with the Adobe Reader bug there is now a widely used client-side application that allows cross-site-scripting... [04 Jan 2007]
Google fixes Gmail address book flaw
News Google has regularly had to fix flaws found in its services. Most of these are relatively new types of weaknesses in web applications - for example, cross-site scripting... [03 Jan 2007]
Google search apps packing 'phishing flaw'
News Jeremiah Grossman, chief technology officer at WhiteHat Security, which specialises in web application flaws and protection, said: "This particular vulnerability is clever because of the encoding hack. [28 Nov 2006]
Yahoo! plugs webmail flaw
News Cross-site scripting flaws are found regularly, including recently in Google's website and earlier this year in Microsoft's Xbox 360 site.... [24 Oct 2005]
Google fixes phishing flaw
News Cross-site scripting flaws are found regularly. The flaw, known as a cross-site scripting vulnerability, existed on... [11 Oct 2005]
Microsoft red faced over web-mail flaw
News Cross-site scripting flaws are errors in website design, not in web browsers, and were discovered more than five years ago. Microsoft has described the... [07 Jun 2005]
Firefox open to exploit code attacks
News The cross-site scripting and remote system access flaws were discovered in Firefox version 1.0.3, but other versions may also be affected, said security company Secunia,... [10 May 2005]
Phishers script their way into online banking
News Online criminals are increasingly using cross-site scripting flaws to inject their own code into legitimate web page URLs, the network security services company said in... [15 Mar 2005]
The Anatomy of Cross Site Scripting
White Paper Cross site scripting (XSS) flaws are a relatively common issue in web application security, but they are still extremely lethal. While this is adequate for prevention,... [22 Feb 2005]
Keep updated for stories matching flaws cross-site scripting via RSS