Re: Cross site scripting @verisign.com and @cybercash.com

From: Tim Morgan (tmorgan-security@kavi.com)
Date: 04/21/02


Date: Sat, 20 Apr 2002 20:56:17 -0700
From: Tim Morgan <tmorgan-security@kavi.com>
To: KF <dotslash@snosoft.com>


> http://www.cybercash.com/>alert('hi')</script>
>
> or
>
>
http://www.verisign.com/
> <http://www.cybercash.com/><script>alert('hi')</script>
>
> Not sure how big a deal this is... but seeing as how the name verisign
> is associated with "Security" I think it should be looked at. This
> didn't work from my Mozilla browser on linux but it did from IE on
> win2k... could be a browser detection method causing the varied results.

I noticed this on CyberCash a few weeks ago, but didn't think much of it
since their site is on the chopping block. Hadn't checked VeriSign yet
though, good find. One interesting point is that CyberCash seems to use
cookies for authentication. At this point in time, AFAIK, you can't glean CC
numbers from the site, but before VeriSign swallowed CyberCash, there
were some interfaces that allowed you to get credit card numbers for
certain transactions. It is scary and pathetic that such things go on.

tim



Relevant Pages

  • Re: Cross site scripting @verisign.com and @cybercash.com
    ... but seeing as how the name verisign ... > is associated with "Security" I think it should be looked at. ... could be a browser detection method causing the varied results. ... Because of the popularity of XSS/CSS holes I have written a FAQ on the subject. ...
    (Vuln-Dev)
  • Re: Cross site scripting @verisign.com and @cybercash.com
    ... but seeing as how the name verisign ... > is associated with "Security" I think it should be looked at. ... could be a browser detection method causing the varied results. ... Because of the popularity of XSS/CSS holes I have written a FAQ on the subject. ...
    (Bugtraq)
  • Cross site scripting @verisign.com and @cybercash.com
    ... but seeing as how the name verisign ... is associated with "Security" I think it should be looked at. ... could be a browser detection method causing the varied results. ...
    (Bugtraq)
  • Cross site scripting @verisign.com and @cybercash.com
    ... but seeing as how the name verisign ... is associated with "Security" I think it should be looked at. ... could be a browser detection method causing the varied results. ...
    (Vuln-Dev)
  • [NEWS] VeriSign "PayFlow Link" Payment Service Security Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The final checkout page of various online shopping cart applications ... vendor's PayFlow Link account at VeriSign for validation. ... Sign up for a free demo PayFlow Link account at VeriSign. ...
    (Securiteam)

Loading