Another MySpace XSS Through an API
...Rosario Valotta found an XSS in MySpace using the mobile API . MySpace being plagued with XSS vulns is really nothing new, but this is actually pretty interesting to me because its the first time I can publically point to a place where the API is the conduit for the attack. Where youd normally be unable to enter JavaScript, on the mobile API...





