Web Hack List

Top 10 winner

Abusing XSLT for Practical Attacks

XSLT 1.0 processors in browsers and on servers leak vendor and file path details, mis-handle large integers and real numbers, and seed random values weakly or not at all. Safari lets a stylesheet fetch cross origin URLs with the user's cookies through the document function, and error messages from document, include and import disclose the first line of local files such as /etc/passwd.

Record

Researcher
Fernando Arnaboldi
Published by
IOActive
Format
Recording
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Fernando Arnaboldi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .