Blog
eBay Patches XSS Flaw that Could Have Allowed Attackers to Steal User Passwords
By David Bisson on Tue, 01/12/2016
eBay has patched a cross-site scripting (XSS) vulnerability that attackers could have exploited in order to steal users' passwords. A researcher who goes by the name MLT explains in a blog post how he was able to exploit a "fairly basic" XSS vulnerability without needing to resort to any additional measures, such as bypassing the WAF, in order to...