Top 10 winner
Abusing XSLT for Practical Attacks
XSLT 1.0 processors in browsers and on servers leak vendor and file path details, mis-handle large integers and real numbers, and seed random values weakly or not at all. Safari lets a stylesheet fetch cross origin URLs with the user's cookies through the document function, and error messages from document, include and import disclose the first line of local files such as /etc/passwd.
Record
- Researcher
- Fernando Arnaboldi
- Published by
- IOActive
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Fernando Arnaboldi, first published at the original source. Preserved copies are kept so the citation survives its host.