Date:
17 May 2007
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting
I seldom add disclosures anymore to WHID, even less XSS disclosures, but since this time they were discovered in banking sites, I thought it was worth it. After all, too many times people think that application vulnerabilities are found only at less "serious" or less "important" web sites where no real damage can occur.
References: