Articles tagués avec Security

16 mai 2008

MessengerFX allows your contacts to take control over your WLM

I have paste some HTML code to a Edouard using MessengerFX, a popular web Windows Live Messenger client based on AJAX, and - surprise, the code has been interpreted. Oh?! A XSS vulnerability ? Yes, and such a big one!
Every  the software’s feature is available through Javascript. Any contact of a MessengerFX user can crash his browser, and futhermore [...]

» Lire la suite...
|