Collected research
Severe XSS in Google and Others due to the JAR protocol issues
Severe XSS in Google and Others Due To The JAR Protocol Issues
Following the jar: origin disclosure, beford showed Google's many open redirects can point a jar: URL at an attacker-hosted archive while keeping google.com as the origin, giving domain-wide XSS across Google services. pdp names the class Web-wide Cross-site Scripting: any site with an open redirect and a Firefox user is exposed until Mozilla patches.
Record
- Document
- Severe XSS in Google and Others Due To The JAR Protocol Issues
- Researcher
- pdp
- Published by
- gnucitizen.org
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .