Back to list
MS14-080 CVE-2014-6365 Technical Details Without "Nonsense"
Jan 13 2015 11:51AM
DiÃ©yÇ? (dieyu dieyu org)
Go to "Acknowledgments" part and search for "CVE-2014-6365"
It says "Dieyu" - that's me.
"Internet Explorer XSS Filter Bypass Vulnerability" is done by...
1. Inject "a href" link into target page.
(Not script, allowed by filter)
2. User clicks this injected link.
3. URL of this injected link puts script into page.
(Filter does not kill it)
(Because it's transaction of the same domain)
David Ross "dross".
2. Hey, if you love my hacking, please reply "nice".
(I do this for free. Love to hear from my readers.)
3. My LinkedIn page: https://www.linkedin.com/in/liuzhiyong
(You can add me there! Recently I took a new name.)
4. My ultimate "flaw": http://dieyu.org/
(You know my style. Comment is welcome!)
[ reply ]
Copyright 2010, SecurityFocus