Web Hack List

Top 10 winner

Universal XSS in IE8

IE8's XSS filter neutralises a detected attack by rewriting one character of the response to a hash. The authors show an attacker can trigger that deliberately with a dummy GET parameter carrying a string already on the page, corrupting an equals sign just before a quoted attribute so injected text becomes a new attribute pair. That gave universal XSS on bing, wikipedia and twitter.

Record

Researcher
Eduardo Vela Nava and David Lindsay
Published by
wokb.cz
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Eduardo Vela Nava and David Lindsay, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .