Changes between Version 2 and Version 3 of Ticket #1859


Ignore:
Timestamp:
2012-11-15T04:15:46Z (12 years ago)
Author:
nejucomo
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #1859 – Description

    v2 v3  
    11**Proof of Concept Attack**
    22
    3 The following proof of concept shows how an html file loaded from any domain into (some) browsers with javascript enabled can inject an attacker controlled script into a grid, and *then* cause the user to execute that script in the domain of the grid:
     3The following proof of concept shows how an html file loaded from any domain into (some) browsers with javascript enabled can inject an attacker controlled script into a grid, and //then// cause the user to execute that script in the domain of the grid:
    44
    55{{{
     
    5555**Related Tickets**:
    5656
    57 * #615 is about illicitly gaining victim capabilities; whereas this ticket is about bootstrapping and attack and/or abusing ambient authority.
     57* #615 is about illicitly gaining victim capabilities; whereas this ticket is about bootstrapping an attack and/or abusing ambient authority.
    5858* #1215 is about adding CORS support and how that may create a vulnerability; this script demonstrates even without CORS support similar vulnerabilities already exist.