Security.allowDomain("*") in SWFs on img.autos.yahoo.com allows data theft from Yahoo Mail (and others)
Unknown
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOneReport Stats
- Report ID: 1171
- State: Closed
- Substate: resolved
- Upvotes: 4