An independent security researcher tested the links and domains associated with About.com and found that almost all of them were vulnerable to cross-site scripting (XSS) and cross-frame scripting (XFS, iframe injection) attacks.

About.com is one of the largest repositories of expert content designed to answer questions about topics ranging from food, health, money and technology, entertainment, careers, parenting and sports. Approximately 100 million users search for information on the information portal each month.
Wang Jing, a PhD student at Nanyang Technological University in Singapore (Department of Mathematical Sciences – MAS, School of Physical and Mathematical Sciences), created a program that is used to check 94,357 links connecting to About.com for security vulnerabilities.
The result was that “at least 99.875% of the links are vulnerable to XSS and Iframe Injection attacks.”
The researcher also found that the search field on the main page could be used in XSS attacks and concluded that all related fields also carry the same vulnerability.
XSS vulnerabilities are among the most common on the internet, but they are also the most dangerous as their exploitation can lead to the theft of user information, such as session cookies and login data. This happens by sending the victim a specially crafted link that contains commands that allow access to the user's content in the browser.
For a successful XFS (iframe injection) attack, information from one domain must access resources from a different domain. However, web browsers incorporate what is called a same-origin policy (SOP), which prevents the mixing of information from different origins.
Therefore, unless the browser has an SOP-type security flaw, such as the one reported for Internet Explorer, the XFS attack is unsuccessful.
Jing said in a blog post on Monday that he reported his findings to About.com on Oct. 19, 2014, but received no response. He also claims that a security update has not yet been applied.
However, the web browsers the researcher used in his tests (IE 10, Firefox 34 and 36, and Chromium 39) are now outdated.
Proof-of-concept tests provided by Jing on IE 11 and the latest versions of Firefox and Google Chrome either produce a 404 error (page not found) or trigger an alert from About.com informing about the malicious attempt, suggesting that administrators have already worked to protect visitors.
