Web Hack List

Other nomination

Google Docs puts Google Users at Risk

Google Docs let any user upload and publish a crossdomain.xml file served from google.com. A Flash object calling System.security.loadPolicyFile() at that uploaded path then gained cross-domain read access to the google.com origin, with no XSS required. The proof of concept dumps the victim's contact list.

Record

Researcher
xssniper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of xssniper, first published at the original source. Preserved copies are kept so the citation survives its host.