| Home : September 16 2013 Computer News : Security company says Nasdaq waited two weeks to fix XSS flaw |
|
Security company says Nasdaq waited two weeks to fix XSS flaw |
September 16, 2013
A Swiss security company said the Nasdaq website had a serious cross-site scripting vulnerability for two weeks before being fixed on Monday, despite earlier warnings.
Ilia Kolochenko, CEO of the Geneva-based penetration testing company High-Tech Bridge, said he repeatedly emailed Nasdaq and warned of the XSS flaw.
“I can basically say I have spammed them,” Kolochenko said in an interview.
Nasdaq.com lets users create accounts and build a profile to monitor stocks and news. Nasdaq said it did not believe the flaw was used by an attacker, and no personal data was compromised.To read this article in full or to leave a comment, please click here
Link: http://www.pcworld.com/article/2048855/security-company-says-nasdaq-waited-two-weeks-to-fix-xss-flaw.html#tk.rss_all
|
|
|
|
|