Top 10 winner
Java Applet Same-Origin Policy Bypass via HTTP Redirect
Java 6 Update 27 and below and Java 7 set an applet's origin from the URL that began the load rather than the URL the redirect ended at. Hosting evil.jar behind a victim site's open redirect therefore let the applet issue cookie-bearing requests back to that site, enabling data theft and CSRF. Patched in the October 2011 CPU as CVE-2011-3546.
Record
- Researcher
- Neal Poole
- Published by
- Neal Poole
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Neal Poole, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .