Collected research
Multiple Browsers Cross Domain Charset Inheritance
Full Disclosure: Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability
Pages without an explicit charset inherit a cross-origin parent frame’s encoding in affected Firefox, IE7 and Opera9 versions. An attacker can frame a target inside a UTF-7 page so encoded input bypasses XSS filters and becomes executable markup. The advisory identifies affected versions, disclosure dates and Firefox’s fix.
Record
- Document
- Full Disclosure: Advisory 03/2007: Multiple Browsers Cross Domain Charset Inheritance Vulnerability
- Researcher
- Stefan Esser
- Published by
- Full Disclosure
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Stefan Esser, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .