Other nomination
Bugs in the Browser: Firefox's DATA URL Scheme Vulnerability
Firefox gives a data: URL the origin of the page that opened it, exactly as it does javascript:, so a base64 data:text/html link posted to a site that only blacklists javascript: yields XSS in that site's origin. pdp shows the one-line anchor proof, notes extensions handling URLs can be pushed to chrome privileges, and argues for scheme whitelisting.
Record
- Researcher
- pdp
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host.