Cross-Site Scripting Hits Major Sites

Hackers are posting cross-site scripting (XSS) flaws found in a number of prominent websites to a hacking site, according to a leading security researcher.
Jeremiah Grossman, WhiteHat Security CTO, told that links for Dell, MSN, HP, Apple, Myspace, YouTube, MSN, Cingular, etc. are posted as having XSS flaws.
Grossman said XSS flaws are now the No. 1 flaw on Mitre's Common Vulnerabilities and Exposures (CVE) site - a considerable growth from 12 months ago.
"XSS is now No.1. It literally took one year and probably less to reach No. 1,"...
» Read the rest of the post



