Sunday, June 3, 2012

Using POST method to bypass IE-browser protected XSS

Up until now,  XSS prevention has been built in some popular browsers: Chrome, Safrai and Internet Explorer 8+.

We found Chrome and Safari prevent both POST and GET-based XSS.

Unfortunately, IE does not prevent POST-based XSS.

Get-Based XSS filtered by IE XSS Filter

POST-based XSS unfiltered by IE XSS Filter

No comments:

Post a Comment