OAuth + ../ + postMessage bug = account takeover #24, WriteupsYou are unauthorized to view this page.
Bypassing URL blocklists in Java #24, Server-side hacking techniquesYou are unauthorized to view this page.