Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

A McAfee spokeswoman said the company rates XSS vulnerabilities less severe than SQL injections and other types of security bugs. “Currently, the presence of an XSS vulnerability does not cause a web site to fail HackerSafe certification,” she said. “When McAfee identifies XSS, it notifies its customers and educates them about XSS vulnerabilities.”

Dan Goodin

Tagged , ,

1 comment

  1. Really ? If McAfee have this backwards an attitude towards XSS vulnerabilities, then do they even bother to identify XSRF problems ?

    Mark Ng - 18th May 2008 12:41 - #

Comments are closed.
A django site