Another MySpace hole
Justin Lavoie came up with a rather interesting DOM based XSS vector for MySpace using String.fromCharCode inside of an improperly sanitized parameter. Pretty tricky. Nice job, Justin!


Justin Lavoie came up with a rather interesting DOM based XSS vector for MySpace using String.fromCharCode inside of an improperly sanitized parameter. Pretty tricky. Nice job, Justin!