Other nomination
NoScript Bypass - "Reflective XSS" through Union SQL Poisoning Trick
An advisory reporting that NoScript up to 2.0.5.1 fails to flag reflected XSS when the payload arrives through a SQL UNION injection. Hex-encoding the script in a union SELECT column means the request never carries recognisable markup, so the filter passes it while the database reflects it back as live HTML; 2.0.6 remained vulnerable.
Record
- Researcher
- Rohit Bansal
- Published by
- Google Groups
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Rohit Bansal, first published at the original source. Preserved copies are kept so the citation survives its host.