Collected research
Google Docs puts Google Users at Risk
Billy (BK) Rios » Google Docs puts Google Users at Risk
Google Docs let any user upload and publish a crossdomain.xml file served from google.com. A Flash object calling System.security.loadPolicyFile() at that uploaded path then gained cross-domain read access to the google.com origin, with no XSS required. The proof of concept dumps the victim's contact list.
Record
- Document
- Billy (BK) Rios » Google Docs puts Google Users at Risk
- Researcher
- xssniper
- Published by
- xs-sniper.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of xssniper, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .