Security flaw found in numerous famous applications from big companies, such as Google, MSN, etc. Applications that affected are namely Google Maps, Gmail, AOL’s AIM Mail, Flikr and MSN Virtual Earth and so on.
This security flaw was actually found in a toolkit for developing those affected applications. The toolkit is called CPAINT, which is used to create applications using AJAX, which stands for Asynchronous JavaScript and XML. It is is an approach to putting more dynamic interactivity into Web applications using a combination of HTML, CSS, Document Object Model, JavaScript, and XMLHttpRequest.
Quoted:
The CPAINT flaw could allow an attacker to execute malicious code on a server running CPAINT, or running an application built using CPAINTThe AJAX approach has been adopted by a number of Web developers, the best known of them being Google, whose Google Maps, Google Suggest, Gmail and other applications use AJAX, although Google has since stated that Gmail is not affected. Other high-profile AJAX-based services include Microsoft’s MSN Virtual Earth, Yahoo’s Flickr and AOL’s AIM Mail. Many lesser-known services have also adopted AJAX, such as Swiss mapping service map.search.ch and invoicing program Blinksale.
The bug affects ALL existing versions of CPAINT, both the ASP and PHP implementations. The project issued a patch fixing the issue, CPAINT v1.3-SP, and is creating a more comprehensive fix for the forthcoming version 2.0.0.
So if you have any project using CPAINT, don’t forget to update to the latest version before it is too late. ![]()
Blogsphere: TechnoratiFeedsterBloglines
Bookmark: Del.icio.usSpurlFurlSimpyBlinkDigg
RSS feed for comments on this post
Best Deal Ads :
Recent Posts :
What? Intel Pentium D Is Actually Two Pentium 4 !!San Francisco City Going Entirely Wireless
Fold n' Drop Your Windows
Counter Strike Guinness World Record
New Worm Shuts Down PC
A9.com Has Its Own Map
New IE 7 Logo
MSN Messenger 7.5 BETA
Upgrade To WordPress 1.5.2
Weekly Highlights [Aug 8, 2005 - Aug 14, 2005]
Related Posts :
Another Critical IE Bug
There were a few critical security flaws found on both...
Why Firefox keeps on releasing new version?
Ever wonder why I strongly recommend Firefox and why it...
Security Flaw In Hyper-Threading !!
Well, I need to clarify again because this post is...
Apple Macintosh In 1984
Saw a collection of old advertisements of Apple Macintosh back...
Firefox 1.0.3 Will Be Launched Very Soon
The Mozilla Foundation plans to release a new version of...















