Simon Willison’s Weblog

Subscribe

17th May 2008

A McAfee spokeswoman said the company rates XSS vulnerabilities less severe than SQL injections and other types of security bugs. "Currently, the presence of an XSS vulnerability does not cause a web site to fail HackerSafe certification," she said. "When McAfee identifies XSS, it notifies its customers and educates them about XSS vulnerabilities."

Dan Goodin

Recent articles

This is a quotation collected by Simon Willison, posted on 17th May 2008.