Web Hack List

Other nomination

NoScript Bypass - "Reflective XSS" through Union SQL Poisoning Trick

An advisory reporting that NoScript up to 2.0.5.1 fails to flag reflected XSS when the payload arrives through a SQL UNION injection. Hex-encoding the script in a union SELECT column means the request never carries recognisable markup, so the filter passes it while the database reflects it back as live HTML; 2.0.6 remained vulnerable.

Record

Researcher
Rohit Bansal
Published by
Google Groups

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Rohit Bansal, first published at the original source. Preserved copies are kept so the citation survives its host.