Collected research
Exploiting XSS in Ajax Web Applications
JSON endpoints that reflect input are exploitable in Internet Explorer despite an application/json content type, because IE content-sniffs on the apparent file extension. Appending .htm, /.html, ;.html or .cgi?a.html to the path makes the response render as HTML and the reflected script run. The fix is output encoding plus X-Content-Type-Options: nosniff.
Record
- Researcher
- superevr
- Published by
- Superevr
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of superevr, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .