Web Hack List

Collected research

Carlos Munoz -- Bypassing Internet Explorer's Anti-XSS Filter

Bypassing Internet Explorer's Anti-Cross Site Scripting Filter

Internet Explorer's reflective XSS filter only inspected data that would execute immediately, and marked anything else trusted for later requests. Injecting a script tag with parts written as HTML decimal or hexadecimal character references landed harmlessly in an attribute, and the browser then decoded it when following the resulting iframe src, form action or link, executing unfiltered.

Record

Document
Bypassing Internet Explorer's Anti-Cross Site Scripting Filter
Researcher
Carlos Munoz
Published by
WhiteHat Security
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Carlos Munoz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .