Collected research
HTML5 XSS
The new HTML5 audio and video tags carry event handlers that fire automatically on an invalid source, giving XSS without user interaction. The vectors <video src=1 onerror=alert(1)> and <audio src=1 onerror=alert(1)> evade filters that blacklist known HTML tags, with further handlers such as onloadedmetadata and ontimeupdate also usable.
Record
- Researcher
- Gareth Heyes
- Published by
- thespanner.co.uk
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .