Cerulean Lulamoon-Spark (ceruleansparkold)'s status on Sunday, 02-Sep-12 20:17:51 UTC

  1. @minti Youtube only sanitised the first script-tag, so if you did <script> <script> it'd allow you to post arbitrary JS in youtube comments. You can only imagine the field day /b/ had.

    Sunday, 02-Sep-12 20:17:51 UTC from web in context