Other nomination
Dont Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets
Script gadgets are legitimate JavaScript fragments inside popular frameworks that pick up injected, script-free HTML and turn it into executing code. Because the injected markup carries no script tag or event handler, HTML sanitisers, web application firewalls, browser XSS filters and CSP all let it through. The authors find such gadgets in most modern frameworks and across many live sites.
Record
- Researcher
- Sebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava and Martin Johns
- Published by
- raw.githubusercontent.com
- Date
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host.