Web Hack List

Collected research

Wormable XSS www.bing.com. XSS on www.bing.com context via Maps…

Wormable XSS www.bing.com

Bing's /maps/configurable endpoint takes a ?config= URL and loads that JSON from any host, and the config's addLayerFromURL then fetches an attacker-hosted KML file whose placemark description carries raw HTML. The KML blacklist regex that is supposed to stop this misses mixed case, so a link href of jAvAsCriPt:(confirm)(1337) survives and runs script in the www.bing.com origin - the origin other Microsoft services accept requests from.

Record

Document
Wormable XSS www.bing.com
Researcher
pedbap
Published by
Medium
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of pedbap, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .