Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Unpatched Wordpress Instance on Yahoo Blog Leads to Cookie Theft (bitdefender.com)
18 points by georgek1029 on Feb 1, 2013 | hide | past | favorite | 1 comment


Yikes. Any site with a publicly accessible swfupload.swf is open to XSS.

https://nealpoole.com/blog/2012/05/xss-and-csrf-via-swf-appl...




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: