Subscribe to RSS - Abuse of Functionality

Abuse of Functionality

Share/Save

A woman exploited a bug in QVC shopping network web site to get, without paying, more than 1800 items worth $412,000 items from the March to November 2005. The glitch enabled her to cancel orders she placed at a specific time and still get the product.

Additional information:

Attack Method: 
Incident Outcome: 
Share/Save

A bug in MySpace allowed a single click on an incoming bulletin by a person to forward it to all his contacts, making spreading a worm (or any content for that matter) too easy.

Additional information:

Share/Save

An XSS when receiving notification of an incoming IM message. Additionally it is possible to send an IM message to somebody who has blocked such messages by pretending to be answering a message from him.

Additional information:

Incident Outcome: 
Share/Save

E-mail addresses of other customers displayed by mistake, no hacking was required

Additional information:

Attack Method: 
Incident Outcome: