5 ms·
This has been demo'd a long time ago already [1], and it seems they haven't done anything yet ? Wtf. [1] http://www.davidnaylor.co.uk/massive-twitter-cross-sit
by Seldaek 16y ago
This has been demo'd a long time ago already [1], and it seems they haven't done anything yet ? Wtf.
[1] http://www.davidnaylor.co.uk/massive-twitter-cross-site-scripting-vulnerability.html http://www.davidnaylor.co.uk/massive-twitter-cross-site-scri...
- b3n 16y agoIt was fixed, but now it's back again... > The problem is similar to one described last August by James Slater. That time around the issue was with the application URL, this time it appears the application name is the issue.
- fname 16y agoEDIT: nevermind.. you're right. WTF is right.
- Sejanus 16y agoDifferent field, application name instead of application URL.