Collected research
JavaScript Code Flow Manipulation
IBM Application Security Insider: JavaScript Code Flow Manipulation, and a real world example advisory
CVE-2008-2640: every Flex 3 build ships history/historyFrame.html, which does document.write on document.location.href. Direct exploitation fails because processUrl first calls parent.BrowserHistory. The fix is JavaScript flow manipulation - the attacker's parent page names a bogus iframe _ie_firstload, so the child reads an iframe where it expected a JS object and the branch flips.
Record
- Document
- IBM Application Security Insider: JavaScript Code Flow Manipulation, and a real world example advisory
- Researcher
- Ory Segal and Adi Sharabani
- Published by
- blog.watchfire.com
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ory Segal and Adi Sharabani, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .