Date:
18 December 2005
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting
A malicious site can offer users a malformed RSS XML file to be included Yahoo RSS aggregation that would enable stealing Yahoo cookies
References: