Get a Pentest and security assessment of your IT network.

News

Amazon.com Stored XSS via Book Metadata

Amazons Kindle Library is, at the time of writing, vulnerable to Stored Cross-Site Scripting (XSS) attacks. Malicious code can be injected via e-book metadata. Amazon account cookies can be accessed by and transferred to the attacker and the victim’s Amazon account can be compromised. Users most likely to fall victim to this vulnerability are those who obtain e-books from untrustworthy sources and then use Amazon’s “Send to Kindle” service to have them delivered to their Kindle.”]

Source: https://b.fl7.de/2014/09/amazon-stored-xss-book-metadata.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin