
Search found 3 matches
- Mon Jul 20, 2009 10:25 am
- Forum: NoScript Development
- Topic: JAR archive traversal vis SCRIPT src
- Replies: 6
- Views: 3997
Re: JAR archive traversal vis SCRIPT src
Awesome - thx 

- Sun Jul 19, 2009 10:54 pm
- Forum: NoScript Development
- Topic: JAR archive traversal vis SCRIPT src
- Replies: 6
- Views: 3997
Re: JAR archive traversal vis SCRIPT src
Same behavior on "V. 1.9.6.2 - Your Friendly Web Cop"
- Sun Jul 19, 2009 10:50 pm
- Forum: NoScript Development
- Topic: JAR archive traversal vis SCRIPT src
- Replies: 6
- Views: 3997
JAR archive traversal vis SCRIPT src
Hi, I hope this is the right place - I did some testing with JAR files on remote locations and src attributes for script tags. Resulting in this example: <script src="jar://sites.google.com/site/jartest00mario/xss.jar!/attack2.js"></script> http://heideri.ch/jso/jar.html http://sites.googl...