Comment I can edit your blog. (Score 1) 241
To help prove how serious this security hole is, I have set up the following demonstration. You must be using IE, and have checked "remember me" when you logged on to Blogger, or have logged on (and not off) to Blogger in your current browser session.
- Go create a new account at http://www.blogger.com (unless you want me to mess with your real account), check "rememeber me" when you log on.
- Create a new blog, enter you FTP password if you want me to be able to actually publish changes I make.
- Add a blog entry that says you want me (Eric Costello) to add an entry to prove I was there.
- Go to http://www.glish.com/cookies.html.