[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <26563eca0604111134g5cb20c7dlac8360a8a85f433e@mail.gmail.com>
Date: Tue Apr 11 19:34:29 2006
From: dbounds at gmail.com (Darren Bounds)
Subject: GMail, Google Groups XSS Vulnerability
GMail, Google Groups XSS Vulnerability
April 11, 2006
GMail and Google Groups are vulnerable to an cross site scripting
(XSS) attack due to their reliance on Content-Disposition to provide
separation between the HTML file download and application scopes. The
result is the ability for an attacker to send / post a malicious HTML
file attachments which, when read using Internet Explorer, will
execute within the scope of the Google application allowing the theft
of sensitive user content.
A PoC is available on Google Groups at the following URL:
http://groups.google.com/group/Content-Disposition/browse_thread/thread/925106682eb32b2b
This vulnerability is directly related to my posting earlier this week
entitled "Microsoft Internet Explorer Content-Disposition HTML File
Handling Flaw" which can be found at the following URL:
http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/044991.html
Google has been notified.
--
Thank you,
Darren Bounds
Powered by blists - more mailing lists