AJAX Vulnerability Discovered

For several years I've been much more focused on Flex than AJAX, but I wrote AJAX-style apps back in the day, and I've used AJAX on some recent projects. I don't really miss JavaScript very much, to be honest.

That said, I do think AJAX is an interesting idea and I'm glad to see so many companies begin to re-think the way they use the web. When questioned about limitations, development time, cross-browser and accessibility issues, etc. - AJAX enthusiasts are beginning to fire back with solid responses (thanks largely to the ever-growing number of freely available toolkits and libraries). Unfortunately, it looks like there's been a bump in the road, as researchers at Fortify Software (an IT security company) have discovered a nasty vulnerability in AJAX applications - and it appears that all of the popular AJAX packages (including the libraries released by Microsoft, Google, and Yahoo) are susceptible.

Computer Business Review has a decent article summarizing the vulnerability at http://www.cbronline.com/article_news.asp?guid=484BC88B-630F-4E74-94E9-8D89DD0E6606

Comments
Does Spry have this vulnerability? I do not see it on the list in the cited article.
# Posted By Lola LB | 4/3/07 7:01 AM
I'm not positive, and I'll let you know when I'm sure, but my initial guess is that Spry is also vulnerable.
# Posted By Simon Horwith | 4/5/07 12:43 AM
This site is hosted by HostMySite and runs off of BlogCFC - thanks, Ray.