Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

ActiveX + XSS = ActiveXSS Pwnage!

Summary

After finding XSS in web apps running ActiveX plugins, NetSPI chains the two: extracting class IDs from page HTML, resolving the backing DLL via the registry, and fuzzing it with ComRaider.
Published
Collected

original ↗