Vimeo highly vulnerable to CSRF attacks – now fixed
February 12th, 2010 — 1:33am
I recently found, that vimeo.com had a cross-domain policy, that allowed anyone to connect, which was an open invitation for CSRF attacks. I alerted them to the issue, and it has now been fixed.
