Web Hack List

Collected research

Converting unimplementable Cookie-based XSS to a persistent attack

XSS reachable only through a Cookie header is usually written off as unexploitable because no page can make a browser send a modified cookie. Chaining fixes that: a common reflected XSS sets the poisoned cookie value through document.cookie, and the cookie-based flaw then fires on every subsequent login. Two lower-severity bugs combine into a persistent attack that survives across sessions.

Record

Researcher
Jeremiah Grossman
Published by
blog.jeremiahgrossman.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jeremiah Grossman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .