Paypal XSS vulnerability

Paypal was affected by a cross-site scripting (XSS) vulnerability, an exposure that allows a hacker to inject client side script into Web pages viewed by other users.
The hacker would be able to trick a Paypal subscriber into clicking a crafted version of the link and therefore, hijack the user’s session, financial transactions, money transfers etc.
What makes this kind of vulnerability even more tricky is the fact that this is a legitimate URL that could redirect the user to …

