XSS bug affects the “Password Assistance” page, thus becoming the ideal phishing weapon for fraudsters. Seller Central is where sellers who signed up for the “Checkout by Amazon” service can view and manage their orders. With border set to 0 in the tag, it could retrieve a deceitful seller central user login page that logs authentication credentials in cleartext and sends them to the fraudster’s e-mail inbox. “See Me” injected an iFrame tag that retrieves the first page of XSSed.com.”]
Source: http://www.xssed.com/news/127/Secure_Amazon_Seller_Central_password_reset_page_XSSed/

