Collected research
Bugs in the Browser: Firefox's DATA URL Scheme Vulnerability
Bugs In The Browser Firefox's DATA URL Scheme Vulnerability
Firefox gives a data: URL the origin of the page that opened it, exactly as it does javascript:, so a base64 data:text/html link posted to a site that only blacklists javascript: yields XSS in that site's origin. pdp shows the one-line anchor proof, notes extensions handling URLs can be pushed to chrome privileges, and argues for scheme whitelisting.
Record
- Document
- Bugs In The Browser Firefox's DATA URL Scheme Vulnerability
- Researcher
- pdp
- Published by
- gnucitizen.org
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .