Web Hack List

Other nomination

XSS Relocation Attacks through Word Hyperlinking

Enterprise applications that let users upload a Word document and preview it as HTML convert the document's hyperlinks without filtering them. A hyperlink carrying an inline javascript: payload therefore survives the doc-to-HTML conversion and fires in the browser, giving stored XSS and CSRF. Tested against ZOHO Writer, Microsoft Office Live Workspace and Google Docs.

Record

Researcher
Aditya K Sood
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host.