Browse Site by Tags -

Browse Site by Tags

Showing related tags and posts across the entire site.
  • Top Five Web Application Vulnerabilities 5/12/09 - 5/25/09

    1) Novell GroupWise WebAccess Multiple Security Vulnerabilities Novell GroupWise WebAccess is susceptible to multiple vulnerabilities including Cross-Site Scripting and issues of security restriction bypass. Attackers who successfully exploit these vulnerabilities could steal cookie-based authentication...
    Posted to The HP Security Laboratory Blog by mark.painter on 05-27-2009
    Filed under: XSS, PHPCode Injection
  • Top Five Web Application Vulnerabilities 4/28/09 - 5/10/09

    1) Multiple Symantec Products Log Viewer Script Injection Vulnerabilities Multiple Symantec Products are susceptible to browser-exploitable script injection vulnerabilities due to improper sanitization of user-supplied input used in dynamically created content. Successful exploitation would give an attacker...
    Posted to The HP Security Laboratory Blog by mark.painter on 05-11-2009
    Filed under: XSS, SQL Injection
  • Top Five Web Application Vulnerabilities 4/13/09 - 4/26/09

    1) Apache Geronimo Application Server Multiple Remote Vulnerabilities Apache Geronimo Application Server is susceptible to multiple vulnerabilities including Cross-Site Scripting, HTML Injection, directory traversal, and Cross-Site Request Forgery. Successful exploitation could give an attacker the means...
    Posted to The HP Security Laboratory Blog by mark.painter on 04-27-2009
    Filed under: XSS, XSRF
  • Scrubbr - New Stored XSS Finder

    Aspect Security has just released, through OWASP , a new tool called " Scrubbr ". Scrubbr is a Java program which connects to your database (MySQL 5+, MS SQL 2005+, and Oracle) directly and analyzes databases or specific tables looking for XSS strings. The strings are defined via an XML--it...
    Posted to The HP Security Laboratory Blog by Chris Sullo on 02-23-2009
    Filed under: worm, Malware, XSS, JavaScript, Input Validation
  • XSS+phishing in Italian bank hack

    Netcraft is reporting today about a phishing attack leveraging XSS against an Italian bank. From the article (emphasis mine) An extremely convincing phishing attack is using a cross-site scripting vulnerability on an Italian Bank's own website to attempt to steal customers' bank account details...
    Posted to The HP Security Laboratory Blog by Billy on 01-10-2008
    Filed under: XSS, Phishing, hacked
  • SPI Labs advises avoiding iPhone feature

    The Apple iPhone’s Safari web browser has a special feature that allows the user to dial any phone number displayed on a web page simply by tapping the number. SPI Labs has discovered that this feature can be exploited by attackers to perform various attacks, including: Redirecting phone calls...
    Posted to The HP Security Laboratory Blog by Billy on 07-16-2007
    Filed under: XSS, Safari
  • Speaking at Shmoo

    I’m really excited to be speaking at Shmoocon again and especially excited about my presentation this Saturday at 1pm. Javascript Malware for a Gray Goo Tomorrow focuses on the increased scope of damage caused by Cross-Site Scripting (XSS) vulnerabilities in the last year. The Web 2.0 revolution...
    Posted to The HP Security Laboratory Blog by Billy on 03-22-2007
    Filed under: Ajax, XSS, JavaScript