Web Hack List

Other nomination

How To Own Every User On A Social Networking Site

Matt Johansen chains a DOM-based persistent XSS in a social network's profile tag field with missing authorization on the id parameter of the AddTag request. Because every user's id is public in their profile URL, a short injection calling an external script could be written into every profile's DOM, making the flaw wormable.

Record

Researcher
Matt Johansen

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Matt Johansen, first published at the original source. Preserved copies are kept so the citation survives its host.