Collected research
Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames)
Dalili bypasses Firefox's block on dragged javascript: URLs by capitalising the scheme (jAvAscript:) or wrapping it in the feed: protocol. Dropping such a string on an HTML5 drop target inside an iframe redirects the framing page, so the script runs in the parent site's origin. A hidden textarea keeps the payload invisible during selection.
Record
- Researcher
- Soroush Dalili
- Published by
- soroush.me
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .