Security Company Says NASDAQ Waited Two Weeks To Fix XSS Flaw
alphadogg writes "A Swiss security company said the NASDAQ website had a serious cross-site scripting vulnerability for two weeks before being fixed on Monday, despite earlier warnings. Ilia Kolochenko, CEO of the Geneva-based penetration testing company High-Tech Bridge, said he repeatedly emailed NASDAQ and warned of the XSS flaw. 'I can basically say I have spammed them,' Kolochenko said in an interview. A NASDAQ spokesman did not have immediate comment. NASDAQ.com lets users create accounts and build a profile to monitor stocks and news."
What are you laughing at, it's clearly very difficult to fix one XSS vulnerability.
In reality,
Dev gets email, updates code, posts to live website.
He's just 3 weeks behind on email.
There are two types of people in the world: Those who crave closure