Advertisment

Google cautions about Website Optimizer vulnerability

author-image
CIOL Bureau
Updated On
New Update

BANGALORE, INDIA: Google has cautioned Website Optimizer users of a potential security issue with the tool.

Advertisment

According to Google, by exploiting a vulnerability in the Website Optimizer Control Script, an attacker might be able to execute malicious code on a web site using a Cross-Site Scripting (XSS) attack.

The attack can only take place if a website or browser has already been compromised by a separate attack. While the immediate probability of this attack is low, we urge you to take action to protect your site.

A Google release said that the company has has fixed the bug, and all new experiments are not susceptible. However, any experiments you are currently running need to be updated to fix the bug on your site. The comany said that if users have any Website Optimizer scripts from paused or stopped experiments created before December 3, 2010, they will need to to remove or update that code as well.

Advertisment

The release adds that there are two ways to update your code. You can either stop current experiments, remove the old scripts, and create a new experiment, or you can update the code on your site directly.

Google recommends creating a new experiment as it is the simpler method.

Creating a New Experiment

Advertisment
  1.  Stop any currently running Website Optimizer experiments.
  2. Remove all the Website Optimizer scripts from your site.
  3. Create a new experiment as normal. New experiments are not vulnerable.

Also read: Updating the Website Optimizer Control Script Directly



tech-news