Collected research
IMAP Vulnerable to XSS
Wade Alcorn's Inter-Protocol Communication paper shows two protocols can meaningfully talk when the target tolerates errors and the carrier can encapsulate it. An HTTP multipart POST from a browser delivers valid IMAP3 commands to port 220; the server echoes unrecognised commands verbatim, reflecting a script tag back into the browser for cross-protocol XSS, fingerprinting and brute force.
Record
- Researcher
- Wade Alcorn
- Published by
- ngssoftware.com
- Format
- Whitepaper
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Wade Alcorn, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .