Web Hack List

Collected research

Multiple Browsers Cross Domain Charset Inheritance

Full Disclosure: Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability

Pages without an explicit charset inherit a cross-origin parent frame’s encoding in affected Firefox, IE7 and Opera9 versions. An attacker can frame a target inside a UTF-7 page so encoded input bypasses XSS filters and becomes executable markup. The advisory identifies affected versions, disclosure dates and Firefox’s fix.

Record

Document
Full Disclosure: Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability
Researcher
Stefan Esser
Published by
Full Disclosure
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefan Esser, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .