Web Hack List

Collected research

Netflix.com XSRF vuln

[WEB SECURITY] Netflix.com XSRF vuln

Dave Ferguson's October 2006 disclosure of CSRF on Netflix.com. A single hidden image tag adds a DVD to a logged-in visitor's queue; a little JavaScript moves it to the top so it ships before the victim notices. The same class of request could change the account name, address, email and password, or cancel the account outright.

Record

Document
[WEB SECURITY] Netflix.com XSRF vuln
Researcher
Dave Ferguson
Published by
webappsec.org
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dave Ferguson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .