Amazon fixed a critical security vulnerability on its web site that allowed access to user accounts.
The issue affected all of Amazon’s web sites for individual countries around the world.
RELATED STORIES
Security Release for Drupal
Web Site Security Holes
Potential Yahoo Mail XSS Bug
Yahoo Adds HTTPS Support
The vulnerability could inject JavaScript code on the retailer’s server that could then execute in another customer’s browser when they opened the prepared page, said researchers at heise Security.
This cross-site scripting (persistent XSS) allowed attacks on session cookies, which could then lead to access of full names, email addresses and shopping carts in the course of their experiment. The vulnerability could also collect login data (phishing) or spread malware.
The only thing required for the exploit was to make a post in the customer forum with a specially formatted title along the lines of “>

