Web Hack List

Collected research

.Net Cross Site Scripting -- Request Validation Bypassing

.Net Cross Site Scripting - Request Validation Bypassing

ASP.NET Request Validation rejects a tag in a parameter value, but not the same tag written with a leading percent sign, which Internet Explorer still parses as valid markup. Reflecting that value with a style attribute carrying an xss:expression executes script through the filter. Microsoft declined to fix, calling the feature basic input validation.

Record

Document
.Net Cross Site Scripting - Request Validation Bypassing
Researcher
Zamir Paltiel
Published by
quotium.com
Format
Advisory
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Zamir Paltiel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .