cross-site scripting

  1. Solar-Log Base 15 Vulnerability: Security Advisory for Windows Users

    In a world increasingly dependent on interconnected devices, a recent advisory has put a spotlight on a vulnerability that could potentially allow malicious actors to wreak havoc in our homes and businesses. If you're a Windows user who values security—as one should in today's digital...
  2. CISA & FBI Alert: Urgent Steps to Combat Cross-Site Scripting Vulnerabilities

    Introduction According to the CISA (Cybersecurity and Infrastructure Security Agency) and FBI's recent announcement dated September 17, 2024, a new Secure by Design Alert has been released focusing on eliminating Cross-Site Scripting (XSS) vulnerabilities in software systems. This alert stems...
  3. MS15-087 - Important: Vulnerability in UDDI Services Could Allow Elevation of Privilege...

    Severity Rating: Important Revision Note: V1.0 (August 11, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker engineered a cross-site scripting (XSS) scenario by inserting a...
  4. MS15-062 - Important: Vulnerability in Active Directory Federation Services Could Allow...

    Severity Rating: Important Revision Note: V1.0 (June 9, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Active Directory Federation Services (AD FS). The vulnerability could allow elevation of privilege if an attacker submits a specially crafted URL...
  5. Microsoft Anti-Cross Site Scripting Library V4.3

    AntiXSS 4.3.0 helps you to protect your applications from cross-site scripting attacks. Link Removed
  6. Following Spamhaus DDoS Attack, Action Taken. We Seek Your Feedback!

    Hello everyone, Tonight, we implemented CloudFlare, which uses its own content delivery network and content processing. Were the site to go down, content would continue to be available for a number of days, even if our servers that process that data goes down. This is not the first time that we...
  7. MS11-061 - Important: Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege

    Severity Rating: Important - Revision Note: V1.0 (August 9, 2011): Bulletin published.Summary: This security update resolves a privately reported vulnerability in Remote Desktop Web Access. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege...
  8. MS11-061 - Important: Vulnerability in Remote Desktop Web Access Could Allow Elevation of Privilege

    Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Remote Desktop Web Access. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the...
  9. Windows 7 Researchers Finds Dangerous Vulnerability in Skype

    Link Removed
  10. MS11-051 - Important: Vulnerability in Active Directory Certificate Services Web Enrollment Could Al

    Bulletin Severity Rating:Important - This security update resolves a privately reported vulnerability in Active Directory Certificate Services Web Enrollment. The vulnerability is a cross-site scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute...
  11. Microsoft Security Advisory (2501696): Vulnerability in MHTML Could Allow Information Disclosure - 3

    Revision Note: V1.1 (March 11, 2011): Revised Executive Summary to reflect investigation of limited, targeted attacks. Advisory Summary:Microsoft is investigating new public reports of a vulnerability in all supported editions of Microsoft Windows. The vulnerability could allow an attacker to...
  12. Microsoft releases Security Advisory 2501696

    Hello. Today we're releasing Link Removed due to 404 Error, which describesa publicly disclosed scripting vulnerability affecting all versions ofMicrosoft Windows. The main impact of the vulnerability is unintendedinformation disclosure. We're aware of publishedinformation and proof-of-concept...
  13. Apple's Safari updates fix auto-complete vulnerability

    The latest updates to Apple's Safari WebKit-based browser, versions 5.0.1 and 4.1.1, include several new features, such as enabling Safari Extensions and introducing the Safari Extensions Gallery,. They also address a number of security vulnerabilities. In total, the Safari updates close 15...
  14. Windows 7 Critical weaknesses found in four browsers

    Safari, IE, Chrome and Firefox The autocomplete features in Safari, IE, Firefox, or Chrome are vulnerable to ID theft and other attacks. Insecurity expert Jeremiah Grossman is expected to tell a Black Hat conference that the four major browsers have critical weaknesses that have yet to be...
  15. Windows 7 IE 8 XSS filter exposes sites to XSS attacks

    Link Removed The cross-site scripting filter that ships with Microsoft’s Internet Explorer 8 browser can be abused by attackers to launch cross-site scripting attacks on websites and web pages that would otherwise be immune to this threat. According to a Link Removed at this year’s Black Hat...