Web Hack List

Collected research

Crouching Tiger Hidden Payload: Security Risks of Scalable Vector Graphics (The Image That Called Me)

HTML5 requires browsers to render SVG embedded via img tags, CSS or inline, and SVG files are fully functional one-file web applications rather than passive images. The paper shows such images can execute arbitrary JavaScript, that current filtering of uploaded or embedded SVG is circumventable, and measures the impact on Firefox 4, IE9 and Opera 11.

Record

Researcher
Mario Heiderich, Tilman Frosch, Meiko Jensen and Thorsten Holz
Published by
nds.ruhr-uni-bochum.de
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mario Heiderich, Tilman Frosch, Meiko Jensen and Thorsten Holz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .