Web Hack List

Collected research

Google Docs puts Google Users at Risk

Billy (BK) Rios » Google Docs puts Google Users at Risk

Google Docs let any user upload and publish a crossdomain.xml file served from google.com. A Flash object calling System.security.loadPolicyFile() at that uploaded path then gained cross-domain read access to the google.com origin, with no XSS required. The proof of concept dumps the victim's contact list.

Record

Document
Billy (BK) Rios » Google Docs puts Google Users at Risk
Researcher
xssniper
Published by
xs-sniper.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of xssniper, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .