Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Noscript XSS filter bypass

Summary

Gareth Heyes finds a NoScript XSS filter bypass using __defineSetter__ to trigger arbitrary function calls in script context, with window.name delivery across domains. Since patched.
Published
Collected

original ↗

Related coverage

back