Web Hack List

Other nomination

Stored XSS Vulnerability @ Amazon

Amazon's search-inside-this-book feature passed matched book text unfiltered into a tooltipText variable, so script printed in a published book executed when a shopper moused over a search result. Web security books already contain such payloads, making the printed page itself the injection channel into amazon.de, .co.uk and .com.

Record

Researcher
Dirk Wetter

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dirk Wetter, first published at the original source. Preserved copies are kept so the citation survives its host.