Date:
20 February 2006
Incident Type: Vulnerability Disclosure
WASC Threat Classification: Cross-site Scripting
The $a variable in Hotmail's inbox is vulnerable to cross site scripting vulnerability. Exploit requires the victim to open the email message.
References: