Other nomination
MSWord Scripting Object XSS Payload Execution Bug and Random CLSID Stringency
Chrome and WebKit execute the URL passed in an OBJECT element's PARAM value, with or without a CLSID, even though ActiveX class identifiers mean nothing outside IE. A javascript: URI in param name="url" therefore fires as XSS. The post records Chrome's response attributing it to URL prefetching of the data/movie/src param names.
Record
- Researcher
- Aditya K Sood
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host.