Web Hack List

Collected research

HTTP Response Splitting and Data: URI scheme in Firefox

Wisec - The WIse SECurity

Stefano Di Paola chains HTTP response splitting into a data: URI XSS on Firefox. A redirector vulnerable to splitting is made to emit a Refresh header pointing at data:text/html with script in it, and Firefox executes that script in the redirecting site's context, extending pdp's data: URI concerns and Amit Klein's Refresh header work.

Record

Document
Wisec - The WIse SECurity
Researcher
Stefano Di Paola
Published by
wisec.it
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .