Parse and Parse: MIME Validation Bypass to XSS via Parser Differential
lab.ctbb.show | research | #web-security | #xss | #research | #mime | #content-type | #parser-differential | #header-validation | #browser-parsing
Summary
A researcher demonstrates how a single comma in the Content-Type header creates a parser differential between browsers and MIME parsing libraries, letting attackers bypass validation and achieve reflected XSS.
- Published
- Collected
Skip to content