What happens when you mix one of the most evil things in music with the evil that is cross-site scripting? Let’s just say that the potential for shenanigans is endless. Observe the result of entering the following embed tag into an editable column for one of our internal web apps. 1: <embed src=”http://www.youtube.com/v/XZ5TajZYW6Y&hl=en_US&fs=1&rel=0&autoplay=1″ type=”application/x-shockwave-flash” width=”640″ [...]