Web Hack List

Collected research

MSWord Scripting Object XSS Payload Execution Bug and Random CLSID Stringency

Google Chrome/ WebKit - MSWord Scripting Object XSS Payload Execution Bug and Random CLSID Stringency

Chrome and WebKit execute the URL passed in an OBJECT element's PARAM value, with or without a CLSID, even though ActiveX class identifiers mean nothing outside IE. A javascript: URI in param name="url" therefore fires as XSS. The post records Chrome's response attributing it to URL prefetching of the data/movie/src param names.

Record

Document
Google Chrome/ WebKit - MSWord Scripting Object XSS Payload Execution Bug and Random CLSID Stringency
Researcher
Aditya K Sood
Published by
zeroknock.blogspot.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .