Web Hack List

Later archive addition

Steam, Fire and Paste: UXSS via DOM XSS and clickjacking

The write-up chains a DOM-based XSS and clickjacking weakness in the Steam Inventory Helper extension into universal cross-site scripting. A malicious page manipulates privileged extension UI and execution paths to run script in arbitrary origins available to the browser.

Record

Researcher
@IAmMandatory
Published by
The Hacker Blog

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @IAmMandatory, first published at the original source. Preserved copies are kept so the citation survives its host.