Yahoo! fixes webmail flaws

Malicious actions kept at bay...

NEWS Yahoo! has fixed two flaws in its free email system that could have allowed a malicious user to read a victim's browser cookies and change the appearance of some pages.

A representative of the company said the flaws were fixed last month by making changes on the company's Yahoo! Mail servers.

A Yahoo! spokeswoman said: "We were alerted of it at the end of May, early June. There ended up being two variations of the issue: One which we could reproduce in a few days and the other which took a lot of effort to reproduce."

The vulnerabilities are of a type known as cross-site scripting flaws, which typically take advantage scripting languages and misconfigured web servers to launch attacks against a user's computer. The attacks typically redirect the user to another website, allow access to the user's cookies or, sometimes, allow the attacker to run code on the victim's computer.

Yahoo! fixed the flaws in its server code. No patch is required by the Yahoo! Mail users.

Robert Lemos writes for News.com

Comments

There are 2 comments. Join the discussion

  1. 1. junkzz

    Who said, they fixed the bug? You... you are wrong :P I was yesterday on my yahoo , and i cant sign out from mail becuse computer collect cookies from yahoo :P maybe they are infected !!!

    • 20 August 2004 09:21
    • Add comment
  2. 2. anonymous

    Yahhhooooo for yahoo, they fixed the bug........So tryin' to log on for the last hour solid is one of their new yahoo games? Okay? Great????? Yaa who called this fixed? They should be fixed.

    • 28 December 2004 02:20
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters