Web Hack List

Top 10 winner

Java Applet Same-Origin Policy Bypass via HTTP Redirect

Java 6 Update 27 and below and Java 7 set an applet's origin from the URL that began the load rather than the URL the redirect ended at. Hosting evil.jar behind a victim site's open redirect therefore let the applet issue cookie-bearing requests back to that site, enabling data theft and CSRF. Patched in the October 2011 CPU as CVE-2011-3546.

Record

Researcher
Neal Poole
Published by
Neal Poole
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Neal Poole, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .