Collected research
JSON-based XSS exploitation
Internet Explorer falls back to the URL's file extension when a response's declared content-type is missing from the registry MIME database, and application/json is not listed there. Appending path-info such as /.html to the endpoint returns the same JSON body but makes IE render it as HTML, firing reflected XSS in JSON responses. Tested on IE 6-9 over IIS and Apache.
Record
- Researcher
- Adi Cohen
- Published by
- IBM Application Security Insider
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adi Cohen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .