PayPal has patched a critical cross-site scripting vulnerability that a Finnish researcher disclosed late last week. The vulnerability’s potential impact was even more serious than usual because the page was guarded by an Extended Validation (EV) SSL certificate. PayPal was one of the first commercial sites to use an EV, introduced to reassure users that an online site is legitimate and not a fake hosted by phishers. The payment arm of eBay Inc. said today it had plugged the hole, which was not used in any phishing attacks.”]

