Web Hack List

Other nomination

Wormable XSS www.bing.com. XSS on www.bing.com context via Maps…

Bing's /maps/configurable endpoint takes a ?config= URL and loads that JSON from any host, and the config's addLayerFromURL then fetches an attacker-hosted KML file whose placemark description carries raw HTML. The KML blacklist regex that is supposed to stop this misses mixed case, so a link href of jAvAsCriPt:(confirm)(1337) survives and runs script in the www.bing.com origin - the origin other Microsoft services accept requests from.

Record

Researcher
pedbap
Published by
Medium
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of pedbap, first published at the original source. Preserved copies are kept so the citation survives its host.