Top 10 winner
Abusing XSLT for Practical Attacks
XSLT 1.0 processors in browsers and on servers leak vendor and file path details, mis-handle large integers and real numbers, and seed random values weakly or not at all. Safari lets a stylesheet fetch cross origin URLs with the user's cookies through the document function, and error messages from document, include and import disclose the first line of local files such as /etc/passwd.
Record
- Researcher
- Fernando Arnaboldi
- Published by
- IOActive
- Format
- Recording
- Topic
- Other
In the archive
Related sources
- Abusing XSLT for Practical Attacks (White Paper) Whitepaper
- Abusing XSLT For Practical Attacks
- DEF CON 23 - Fernando Arnabold - Abusing XSLT for Practical Attacks
Tags
This page is the archive's own catalogue record. The research is the work of Fernando Arnaboldi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .