A security flaw reported on Facebook earlier this year that allowed an attacker to post comments on someone else's Timeline without permissionis still in place ten months later.
Last year, researcher Vivek Bansal disclosed the vulnerability to Facebook’s security team, showing how access tokens for mobile apps could be used to post to someone else’s Timeline without the necessary permission. (Note that an app cannot “post” text or links to a user’s Timeline without the “required permission from the account holder.”)
Vulnerability still exists ten months later (Video)
For pointing out this bug to Facebook, Bansal received a $2,000 reward and was inducted into the Hall of Fame of researchers who have identified serious problems in the social networking platform’s security mechanisms. However, it seems that the vulnerability either reappeared in code modifications, or someone forgot to fix it – with the first version being the most prevalent.
Recently, Bansal ran the same script he used to initially demonstrate the bug and noticed that everything worked as if no changes had been made. A video posted to YouTube (see below) last Tuesday showed that the vulnerability was still active. When Bansal was asked if he had tested the script on a more recent date to see if the vulnerability was still there, he replied that the most recent test he had done was on Monday, and the flaw was still present.
It's hard to believe that Facebook paid the researcher a fee, and its engineers forgot to patch the vulnerability – although it's not impossible. The more likely scenario, however, is that they forgot to re-examine the patch at a later date. This theory is bolstered by the fact that Bansal received an email from Facebook earlier this year informing him that the vulnerability had been patched and he was free to publish his findings. Check out the recent demonstration of the bug:

