![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE82S-Z_tlgLSo9ZrpWfwvxsMu8QFGGiZv7if0egJTtFTsq_-XXylqxiIhbAy8t5auLWQHk_k_tgbM1rHaqlaK4T4ZOWRFiHVhEAoYVGhwWCzwPlsFIncRXG4Mg2DxpgJYRcnEdRFI6PM/s200/Skype+Vulnerability+security+flow.jpg)
attackers to hijack skype customer sessions via cross site scripting. Successful exploitation of the client-side vulnerability can result in session hijacking & account steal.
They reported about the vulnerability on Nov 4 ,2011.
Skype patched the Vulnerability on Nov 10, 2011. Vulnerability-Lab published the information on Nov 11,2011.
Vulnerability Information:
- Target: Skype Website
- Type: XSS(Non-Persistent)
- Alert Level: Low
- Status: Patched.
- Discovered By: Aditya Gupta @ Vulnerability-Lab