NEWS Yahoo! has fixed two flaws in its free email system that could have allowed a malicious user to read a victim's browser cookies and change the appearance of some pages.
A representative of the company said the flaws were fixed last month by making changes on the company's Yahoo! Mail servers.
A Yahoo! spokeswoman said: "We were alerted of it at the end of May, early June. There ended up being two variations of the issue: One which we could reproduce in a few days and the other which took a lot of effort to reproduce."
The vulnerabilities are of a type known as cross-site scripting flaws, which typically take advantage scripting languages and misconfigured web servers to launch attacks against a user's computer. The attacks typically redirect the user to another website, allow access to the user's cookies or, sometimes, allow the attacker to run code on the victim's computer.
Yahoo! fixed the flaws in its server code. No patch is required by the Yahoo! Mail users.
Robert Lemos writes for News.com





Comments
There are 2 comments. Join the discussion
1. junkzz
Who said, they fixed the bug? You... you are wrong :P I was yesterday on my yahoo , and i cant sign out from mail becuse computer collect cookies from yahoo :P maybe they are infected !!!
2. anonymous
Yahhhooooo for yahoo, they fixed the bug........So tryin' to log on for the last hour solid is one of their new yahoo games? Okay? Great????? Yaa who called this fixed? They should be fixed.