Web Hack List

Other nomination

Bugs in the Browser: Firefox's DATA URL Scheme Vulnerability

Firefox gives a data: URL the origin of the page that opened it, exactly as it does javascript:, so a base64 data:text/html link posted to a site that only blacklists javascript: yields XSS in that site's origin. pdp shows the one-line anchor proof, notes extensions handling URLs can be pushed to chrome privileges, and argues for scheme whitelisting.

Record

Researcher
pdp

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host.