I found out about this yesterday when I was searching some product on Indiatimes Shopping website. It is very common security problem, it is basically a mistake in the coding part. It is called as Cross-Site Scripting (XSS).
I have informed Indiatimes about it but till now I haven’t got any response from them
What is this security hole all about?
In simple words, a person can ask you to click on the link and once you click on it, he can do whatever he wants…he can show Login Page or page asking for credit card details…
And once you enter the details..everything will be mail to him…infact he may try to do lot more than that..he may try to exploit the loopholes in your system…
I have submitted this to BugTraq also…
Wanna read technical Details? Sure…thing..click on “More” link…
Read more…
iMobilePlaza.com The Leading Cell Phone Wholesaler & Retailer, View Our Mobile Phones Now.
