Global Security Watch > BUG: XSS Security flaw in BaseCamp Messages

Untitledhttp://simonwillison.net/2008/Jun/26/bug/ [Untitled] BaseCamp lets users include HTML and JavaScript in messages, on the basis that anyone with a BaseCamp account is a trusted party. I’m not convinced: you could use this to circumvent .

Some related posts from Technorati and Google.

Comments on Simon Willison's Webloghttp://simonwillison.net/2008/Jun/26/bug/#c39500 [Comments on Simon Willison's Weblog] Topbit on BUG: XSS Security flaw in BaseCamp Messages: It's been ...: Topbit on BUG: XSS Security flaw in BaseCamp Messages:. It's been that way for years - I posted an example to their forums that did a Javascript pop-up alert - literally, three years ago.

Reflected tags on Technorati: Blog, ,