# Froogle/Gmail security hole

**URL:** https://forum.kirupa.com/t/froogle-gmail-security-hole/76111
**Category:** random
**Created:** [January 14, 2005, 9:32pm UTC](https://forum.kirupa.com/t/froogle-gmail-security-hole/76111 "2005-01-14T21:32:55Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Maizoon](https://avatars.discourse-cdn.com/v4/letter/m/3d9bf3/32.png) [@Maizoon](https://forum.kirupa.com/u/Maizoon)
#### Post date: [January 14, 2005, 9:32pm UTC](https://forum.kirupa.com/t/froogle-gmail-security-hole/76111/1 "2005-01-14T21:32:55Z")

</div>

> 

By embedding JavaScript in a URL pointing to Froogle, a hacker can gain access to the user’s Gmail account. The JavaScript redirects the browser to a malicious web site, where the hacker can read the user’s cookie, which contains personal information, such as purchase history, user name and password for Google services.

[http://www.aviransplace.com/index.php/archives/2005/01/13/serious-flaw-in-froogle-reveals-gmail-accounts/](http://www.aviransplace.com/index.php/archives/2005/01/13/serious-flaw-in-froogle-reveals-gmail-accounts/)

[http://net.nana.co.il/Article/?ArticleID=155025&sid=10](http://net.nana.co.il/Article/?ArticleID=155025&sid=10)

> **[Gmail accounts 'wide open to exploit' - report](https://www.theregister.com/2004/10/29/gmail_vuln/)**
>
> Cookie monster bites web mail service
