Collected research
Converting unimplementable Cookie-based XSS to a persistent attack
XSS reachable only through a Cookie header is usually written off as unexploitable because no page can make a browser send a modified cookie. Chaining fixes that: a common reflected XSS sets the poisoned cookie value through document.cookie, and the cookie-based flaw then fires on every subsequent login. Two lower-severity bugs combine into a persistent attack that survives across sessions.
Record
- Researcher
- Jeremiah Grossman
- Published by
- blog.jeremiahgrossman.com
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .