No Comments »

XSSed have published reports of multiple HSBC domains that are open to Cross Side Scripting (XSS) attacks that could allow a phisher to embed a malicious site within a genuine HSBC page.

At the time of writing, most of HSBC’s Web real estate were still vulnerable despite being notified months ago.