Date:
21 December 2005
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting
A redirection to an error page on Google.com includes values sent by the the user. This vulnerability allows phishers to send an e-mail with links to Google that will include their attack page.
References: