Hacker News new | past | comments | ask | show | jobs | submit login
Unpatched Wordpress Instance on Yahoo Blog Leads to Cookie Theft (bitdefender.com)
18 points by georgek1029 on Feb 1, 2013 | hide | past | favorite | 1 comment



Yikes. Any site with a publicly accessible swfupload.swf is open to XSS.

https://nealpoole.com/blog/2012/05/xss-and-csrf-via-swf-appl...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: