Top 10 winner
All is XSS that comes to the .NET
ASP.NET still accepts a cookieless session segment such as (A(...)) anywhere in a URL path, and Control.ResolveUrl copies that attacker-controlled segment into every app-root-relative URL it emits. Injecting a quote and an event handler there escapes the src or href attribute for XSS, with ES6 template literals supplying payloads that need no parentheses, plus or slash.
Record
- Researcher
- @phaldrzynski and Paweł Hałdrzyński
- Published by
- blog.isec.pl
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @phaldrzynski and Paweł Hałdrzyński, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .