Web Hack List

Other nomination

Under the Beamer

DOM clobbering gadget in a widget library. Because named items of an HTML collection are not writable, injected elements sharing an identifier stop the library assigning its own escaping function; a second gadget removes the clobbering node so escaping is skipped, and a clobbered domain option reaches an iframe source unescaped, giving XSS past DOMPurify.

Record

Researcher
kevin_mizu

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of kevin_mizu, first published at the original source. Preserved copies are kept so the citation survives its host.