Twitter users are vulnerable to a series of computer attacks that range from compromising their Twitter accounts to infecting their computers. Web security researchers at Secure Science have demonstrated code that takes advantage of cross-site scripting, or XSS.
Researcher Eric Wastl, quoted in Information Week, describes the exploit this way, ”Basically, we produce a link and if a Twitter user clicks on it, it allows us to hijack their accounts.”
This is the same kind of vulnerability that plagued users of MySpace until recently and was described by Swedish student Niklas Bivald in a pair of articles written in 2006.
The most serious danger from this kind of vulnerability is that it allows attackers to insert malicious code into Web pages that then can be used to get around access controls. The attacker can then conduct phishing schemes or any other kind of exploit they desire.