Found in August, I tried to alert facebook as quickly as was possible - however I received no further correspondence to my communications. At time of writing, it was possible to exploit both Firefox 3 and IE 7 - by simply using an IFRAME or even an object tag. (Dependant on the browser target) This allows you to overwrite the whole page with your choice of script/embed. Vulnerability was found by accident when I was routing my web traffic via WebScarab with an advanced list of strings to use with the in-built XSS/CSRF tool. ---------------- http://2.channel15.facebook.com/iframe/7/?pv=49&rev=">