Tampilkan postingan dengan label XSS. Tampilkan semua postingan
FileHippo Vulnerable to XSS flaw found by Security researcher
Kamis, 21 Februari 2013
Posted by Unknown
A Pakistani Security Researcher Ali Hasan Ghauri - founder of AHPT has discovered XSS Vulnerability on Filehippo.com main site. Vulnerability still exists
Last time we published news of W3Schools vulnerable to same XSS flaw reported by the security researcher.
[#] - Website:
http://www.sify.com
[#] - Vulnerable link (POC):
http://www.filehippo.com/it/download_ccleaner/%27%22--%3E%3C/style%3E%3C/script%3E%3Cscript%3Ealert%28%22XSS%20By%20Ali%20Hasan%20Ghauri%22%29%3C/script%3E
[#] - Vulnerability Type:
XSS (Cross Site Scripting)
[#] - Status:
Not Fixed [Critical]
[#] - Tested on:
Firefox 18.0.1
The Youngest Pakistani Security Researcher "Ali Hasan Ghauri" (AHPT) also Found Vulnerabilities on Big Tech Sites on Skype , Adobe, Asia Cnet, Yellowpages, visualstudiomagazine ,Filehippo ,CnetDownloads, US.Acer, W3Schools, Hamariweb & Many More.
About Filehippo:
FileHippo is an Internet download website that offers open source, freeware, and shareware programs for Windows. It does not accept user uploaded files.The website also offers its own software, FileHippo Update Checker, a free program that scans a computer and then reports out-dated software in a web-page, offering links to updated versions.
According to Quantcast, FileHippo receives more than three million US visitors each month and Alexa lists FileHippo among the 700 most visited websites worldwide.
More News of XSS flaw can be found here.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: FileHippo Vulnerable to XSS flaw found by Security researcher
One of the subdomain (http://groups.adobe.com) of Abode site is vulnerable to XSS. The vulnerability is still not fixed by Adobe. Ethical hackers reported vulnerability a few days ago but they failed to respond. We got email from Ethical Indians.
Since the Bug Bounty Program started by companies, hackers are continually hunting different types of vulnerabilities of different top profile sites. Some site lists hacker on hall of fame page for the Bug Bounty and other offer reward for Bug bounty.
Web site:
http://groups.adobe.com
Vulnerability Type:
Cross Site Scripting (XSS)
Vulnerable Link:
http://groups.adobe.com/index.cfm?event=page.badpage&pageid=%3Cscript%3Ealert%28/Ethicalindians/%29%3C%2Fscript%3E
Status:
Not Fixed (No Reply)
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Adobe Vulnerable to XSS flaw
W3Schools XSS vulnerability Found by the youngest Security Researcher
Minggu, 03 Februari 2013
Posted by Unknown
A Pakistani Student "Ali Hasan Ghauri" (AHPT) who is 14 years old, The Youngest Security Researcher has discovered XSS (Cross-Site Scripting) Vulnerability on http://www.w3schools.com main site. Below is the Screen Shot of XSS.
The Youngest Pakistani Security Researcher "Ali Hasan Ghauri" (AHPT) also Found Vulnerabilities on Big Tech Sites on Skype , Adobe, Asia Cnet, Yellowpages, visualstudiomagazine ,Filehippo ,CnetDownloads, US.Acer, W3Schools, Hamariweb & Many More.
Above just polpular sites are mentioned But The Youngest Security Researcher "Ali Hasan Ghauri" (AHPT) has found 250+ Vulnerable Sites & reported to them by giving the Security as well .
About W3Schools:
W3Schools is a web developer information website, with tutorials and references relating to web development topics such as HTML, CSS, JavaScript, PHP, and SQL.
Update:
XSS flaw on W3Schools fixed now.
Rating: 4.5
Reviewer: Unknown
ItemReviewed: W3Schools XSS vulnerability Found by the youngest Security Researcher
