Collected research
NoScript Bypass - "Reflective XSS" through Union SQL Poisoning Trick
NoScript (2.0.5.1 < less ) - Bypass "Reflective XSS" through Union SQL Poisoning Trick (SQLXSSI)
An advisory reporting that NoScript up to 2.0.5.1 fails to flag reflected XSS when the payload arrives through a SQL UNION injection. Hex-encoding the script in a union SELECT column means the request never carries recognisable markup, so the filter passes it while the database reflects it back as live HTML; 2.0.6 remained vulnerable.
Record
- Document
- NoScript (2.0.5.1 < less ) - Bypass "Reflective XSS" through Union SQL Poisoning Trick (SQLXSSI)
- Researcher
- Rohit Bansal
- Published by
- Google Groups
- Topic
- XSS
In the archive
Related sources
- Before you continue to YouTube Recording
Tags
This page is the archive's own catalogue record. The research is the work of Rohit Bansal, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .