http://msujaws.wordpress.com/2011/02/26/javascript-injection-proof-of-concept/
Forgetting to validate user input can allow a vector for an attacker to enter in arbitrary JavaScript that will be executed on another users computer. In this video, I show a simple attack that allows the attacker to place their own content to appear on the victims machine.
Link to this comment:
All Comments (0)