Kid hackers break XSS defences, find hack hole in 2 million websites

EnviableOne

XSS and CSRF along with SQLI are all preventable by good programming. the problem is any kid reckons they can nock something up by pulling one module from here, another from there and expecting them to work, without either the understanding or will to manage the interactions.

I am off on my high horse again, but if the origonal coders were worth their salt, the holes would not have been there.

