Noscript XSS filter bypass
Summary
Gareth Heyes finds a NoScript XSS filter bypass using __defineSetter__ to trigger arbitrary function calls in script context, with window.name delivery across domains. Since patched.
- Published
- Collected
Skip to content