Web Hack List

Top 10 winner

All is XSS that comes to the .NET

ASP.NET still accepts a cookieless session segment such as (A(...)) anywhere in a URL path, and Control.ResolveUrl copies that attacker-controlled segment into every app-root-relative URL it emits. Injecting a quote and an event handler there escapes the src or href attribute for XSS, with ES6 template literals supplying payloads that need no parentheses, plus or slash.

Record

Researcher
@phaldrzynski and Paweł Hałdrzyński
Published by
blog.isec.pl
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @phaldrzynski and Paweł Hałdrzyński, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .