Instead of going for Cross Site Scripting, Remote Code Execution, SQL Injection, etc. I decided to find clickjacking in google and facebook. Clickjacking is one of the lowest paid, mostly out of the scope and underestimated vulnerability by organisations. What is Clickjacking ? Unknowingly performing some sensitive actions on a webpage embedded(mostly in iframes) in any webpage with different or s