ActiveX + XSS = ActiveXSS Pwnage!
netspi.com | vulnerability | #pentesting | #fuzzing | #xss | #activex | #comraider | #client-side-attacks
Summary
After finding XSS in web apps running ActiveX plugins, NetSPI chains the two: extracting class IDs from page HTML, resolving the backing DLL via the registry, and fuzzing it with ComRaider.
- Published
- Collected
Skip to content