Grumpy Security Guy

I’ve suffered the tortures of the damned

Grumpy Security Guy header image 2

Mastercard.com NOT PCI Compliant

January 5th, 2008 ·

Someone has found an XSS vulnerability on mastercard.com. The place it was found, the search function, is a notorious location for XSS vulnerabilities. The XSS payload that triggers the vulnerability leads me to believe that there was a fair amount of filtering going on but I guess not enough.

Who does Mastercard pay PCI penalties to?

If you enjoyed this post, make sure you subscribe to my RSS feed!

Tags: web site security