[Security-news] SA-CONTRIB-2014-092 - Services - Cross Site Scripting, Access bypass