Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Redefining Impossible: XSS without arbitrary JavaScript

Summary

Solving an 'impossible' XSS lab: with the payload confined to a single-quoted string and a tiny charset, Luan Herrera exfiltrates the cookie via side-channel techniques, not arbitrary JavaScript.
Published
Collected

original ↗

Related coverage

back