Friday, December 19, 2008

AmericanExpress.com 2day (0day+2)


AMEX claims to have fixed all their security issues two days ago. But did they??? No, of course not. The two exploits below break their PCI-Compliance status, yet again. I think that this will resurface in the headlines again tomorrow...
http://kristian.hermansen.googlepages.com/amex.post.xss.iframe.visa.html
http://kristian.hermansen.googlepages.com/amex.post.xss.html

1 comments:

william said...

You are in the news at
Dark Reading: http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=212501694