[ UPDATE: Facebook has reversed itself and fixed this vulnerability ]
ZDNet.com reports:
The Register’s Dan Goodin has the scoop on an obvious security vulnerability that’s being ignored by the powers at Facebook.
The issue, as demonstrated by this proof-of-concept, shows how a social network application can be rigged to hijack a Facebook user’s session identification cookies, deliver pop-up messages or change the color of Facebook pages. Continue reading “[now fixed] Facebook refuses to fix obvious security flaw”