Date:
05 April 2006
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting
Forget putting <script> tags in input field. This high tech vulnerability exploits the code handling online/offline flags by inserting a malicious online/offline flag. Awesome.
References: