Search found 2 matches
- Wed Sep 18, 2013 4:44 pm
- Forum: NoScript Support
- Topic: XSS on YouTube
- Replies: 45
- Views: 32230
Re: XSS on YouTube
The tricky thing here is that the site is actually passing entire JavaScript functions around inside URLs, which is exactly what triggers NoScript's anti-XSS filter by design. I wouldn't be surprised if making an exception for this specific Google API usage scenario would allow real XSS abuse. I've...
- Wed Sep 18, 2013 1:55 pm
- Forum: NoScript Support
- Topic: XSS on YouTube
- Replies: 45
- Views: 32230
Re: XSS on YouTube
I also registered to post here. Same thing, but it hosed YT functionality for me.