Web Hack List

Collected research

JSON-based XSS exploitation

Internet Explorer falls back to the URL's file extension when a response's declared content-type is missing from the registry MIME database, and application/json is not listed there. Appending path-info such as /.html to the endpoint returns the same JSON body but makes IE render it as HTML, firing reflected XSS in JSON responses. Tested on IE 6-9 over IIS and Apache.

Record

Researcher
Adi Cohen
Published by
IBM Application Security Insider
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adi Cohen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .