Google is vulnerable to cross site scripting. While surfing around the personalization section of Google I ran accross the RSS feed addition tool which is vulnerable to XSS. The employees at Google were aware of XSS as they protected against it as an error condition, however if you input a valid URL (like my RSS feed) it will return with a JavaScript function containing the URL. . The link for this article located at ha.ckers.org is no longer available. . A deep dive into a cross-site scripting vulnerability within Google that poses risks to user security. Preventative measures and solutions are discussed extensively.. Cross Site Scripting, Google Security, Web Application Risks, XSS Mitigation, Personalization Feed. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.