Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

NoScript Bypass

Summary

Bishop Fox advisory: the expired domain vjs.zendcdn.net remained on NoScript's default whitelist, so re-registering it let attackers run JavaScript despite the add-on in versions before 2.6.9.27.
Published
Collected

original ↗

Related coverage

back