News about cross-site scripting
Features about cross-site scripting
  • Cross-site scripting: An old problem returns

    In May, Web security consultant George Deglin discovered a cross-site scripting (XSS) exploit that involved Facebook's controversial Instant Personalization feature. The exploit ran on Yelp, one of the three sites that Facebook had selected to test Instant Personalization. Deglin was able to obtain not only Facebook profile information shared with Yelp but also the e-mail addresses for that profile's Facebook friends--a potential gold mine for marketers and spammers alike.

    By Robert Vamosi | 18 June, 2010 10:21

    Tags: cross-site scripting, security

Twitter Feed