Date:
26 July 2006
Incident Type: Security Breach
WASC Threat Classification: Cross-site Scripting
Most XSS vulnerabilities are benign. In many cases they are hardly exploitable. In this case Netscape's new digg like shared news site was hacked using a persistent XSS attack, so every viewer of the site was attacked, luckily only to show funny dialog boxes.
References: