Web Hack List

Collected research

Exploiting XSS in Ajax Web Applications

JSON endpoints that reflect input are exploitable in Internet Explorer despite an application/json content type, because IE content-sniffs on the apparent file extension. Appending .htm, /.html, ;.html or .cgi?a.html to the path makes the response render as HTML and the reflected script run. The fix is output encoding plus X-Content-Type-Options: nosniff.

Record

Researcher
superevr
Published by
Superevr
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of superevr, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .