Posted by kiran Maraju on Apr 03
Hi all,
URL redirection vulnerability observed in Facebook. Facebook
application has not sanitized the “redirect” input parameter. if you provide
"redirect" parameter to any third party site then the web page is
redirecting to the third party site. This would aid phishing attacks by using an attacker's dummy site (providing
redirect value to the dummy site).
URL: http://www.facebook.com/ajax/set_as_homepage.php?uid=…
Source: Facebook URL redirection issue




