Posted by theharmonyguy in Facebook | No comments
Bumper Sticker on Facebook
Date: February 4, 2008
Vulnerabilities:
- Able to add a bumper sticker to profile and make it appear to have been sent by any other application user
Progress: Bumper Sticker has been notified.
Details: Illustrating what I posted the other day, I discovered tonight that I could use a query string hack to add bumper stickers and make them appear to be sent from other users. Nothing major, just a possible source of embarassment, but once again shows how even popular applications (Bumper Sticker currently has nearly a million daily active users) can be susceptible to such problems.
No Comments
Trackbacks/Pingbacks