Web Hack List

Other nomination

Carlos Munoz -- Bypassing Internet Explorer's Anti-XSS Filter

Internet Explorer's reflective XSS filter only inspected data that would execute immediately, and marked anything else trusted for later requests. Injecting a script tag with parts written as HTML decimal or hexadecimal character references landed harmlessly in an attribute, and the browser then decoded it when following the resulting iframe src, form action or link, executing unfiltered.

Record

Researcher
Carlos Munoz
Published by
WhiteHat Security

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Carlos Munoz, first published at the original source. Preserved copies are kept so the citation survives its host.