PayPal XSS Vulnerability

by certifiedbug on May 18, 2008

in Internet Security

In an interview with Netcraft, Finnish security researcher Harry Sintonen reported a critical cross-site scripting vulnerability on paypal.com.

Netcraft

The vulnerability is made worse by the fact that the affected page uses an Extended Validation SSL certificate, which causes the browser’s address bar to turn green, assuring visitors that the site – and its content – belongs to PayPal.

Leave a Comment

Previous post:

Next post: