I feel like a lot of the time when I see vulnerabilities I am in awe of the ingenuity of malicious hackers to exploit very precise issues in a codebase.
This time I'm just amazed how anyone could fail to see this coming.
It's nice that Netflix.com is protected, but this is a potential phishing attack (or links just won't work) for any website ending in x?!