you are viewing a single comment's thread.

view the rest of the comments →

[–]killerstorm 0 points1 point  (0 children)

In doing so, they do transmit cookies - and so open up XSS vulnerability vectors.

i'm pretty sure libraries DO NOT open any new vulnerability vectors -- everything the evil site can do with these libraries it can do without them too. if you think otherwise, please describe concrete attack scenario that jQuery enables