Web Hack List

Collected research

Embeding SVG That Contains XSS Using Base64 Encoding in Firefox

ha.ckers.org web application security lab - Archive » Embeding SVG That Contains XSS Using Base64 Encoding in Firefox

nEUrOO's vector: JavaScript embedded in an SVG document, the SVG base64-encoded into a data URI, and the whole thing loaded through an embed tag, which Firefox executes with no plugin installed and no user interaction. RSnake notes the payload travels with the page, so there is no command-and-control server to shut down.

Record

Document
ha.ckers.org web application security lab - Archive » Embeding SVG That Contains XSS Using Base64 Encoding in Firefox
Published by
ha.ckers.org
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .