Web Hack List

Other nomination

MSWord Scripting Object XSS Payload Execution Bug and Random CLSID Stringency

Chrome and WebKit execute the URL passed in an OBJECT element's PARAM value, with or without a CLSID, even though ActiveX class identifiers mean nothing outside IE. A javascript: URI in param name="url" therefore fires as XSS. The post records Chrome's response attributing it to URL prefetching of the data/movie/src param names.

Record

Researcher
Aditya K Sood

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host.