Security gone awry: IE 8 XSS filter exposes sites to XSS attack

Posted by tracyanne on Apr 20, 2010 7:36 AM EDT
ZDNet; By Ryan Naraine
Mail this story
Print this story

The cross-site scripting filter that ships with Microsoft’s Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites and web pages that would otherwise be immune to this threat.

According to a presentation at this year’s Black Hat Europe conference, the issue introduces security problems at several high-profile websites, including Microsoft’s own Bing.com (screenshot), Google.com, Wikipedia.org, Twitter.com (screenshot) and just about any site that lets IE 8 users create profiles.

Full Story

  Nav
» Read more about: Groups: Microsoft; Story Type: News Story

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.