Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
[MacOS X] Insecure eval() in Twitgit and Twitterlex dashboardwidgets Dec 03 2007 11:04PM
Thomas Roessler (tlr w3 org)
Twitgit [1] and Twitterlex [2] are two MacOS X Dashboard widgets
(developed in JavaScript) that can be used to display twitter.com
updates.

Both regularly retrieve data using the Twitter JSON API and parse
whatever is returned with eval(). Both relax the dashboard's
JavaScript sandbox to enable th...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus