October 11, 2005

Google Fixes Phishing Flaw

Google has fixed a security flaw on its website that opened the door to phishing scams, account hijacks and other attacks.

The flaw, known as a cross-site scripting vulnerability, existed on the website for Google's AdWords advertising program and a customer training site, according to security company Finjan Software, which discovered the problem.

Attackers could have exploited the flaw to hijack Google accounts, launch phishing scams or even download malicious code onto users' computers.