I reported this problem to Google in June but I did not get the usual reply saying they were working on it, so I guess it isn't serious enough to be fixed.
The problem is the page for requesting access to a private document. It does not have any protection against being framed, so you can make a private document, trick someone into clicking the button to request access and get an email from Google Docs with their full name and email address. PoC: http://buildism.net/files/GoogleDocsClickjacking2.html
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/