Issue metadata
Sign in to add a comment
|
Security: XSS Auditor doesn't work for XML
Reported by
soroush....@gmail.com,
Jul 15 2016
|
||||||||||||||||||||
Issue descriptionXSS Auditor of Google Chrome doesn't block XSS attacks in XML. An example is shown below: http://0me.me/demo/xss/xml/vuln.xml.php?input=<script xmlns="http://www.w3.org/1999/xhtml">alert(1)</script>&// An exploitation example has been shown here: http://sdl.me/XSSDemo/xss-xml-frames.html Thanks Soroush
,
Oct 22 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by mbarbe...@chromium.org
, Jul 15 2016Mergedinto: 257168
Status: Duplicate (was: Unconfirmed)