Collected research
Relative Path Overwrite
RPO
Relative Path Overwrite adds a trailing slash or fake directory segments to a URL so a page's relative stylesheet reference resolves back to the page itself. The browser then parses the HTML as CSS, and attacker-controlled reflected or stored text beginning with a brace becomes live CSS, giving style injection everywhere and script execution through expressions in older IE modes.
Record
- Document
- RPO
- Researcher
- Gareth Heyes
- Published by
- thespanner.co.uk
- Topic
- Other
In the archive
Related sources
- Detecting and exploiting path-relative stylesheet import (PRSSI) vulnerabilities
- ActiveScan++: Augmenting manual testing with attack proxy plugins (Slides) Slides
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .