Re: [Full-disclosure] [WEB SECURITY] Universal XSS with PDF files: highly dangerous
- From: M.B.Jr. <marcio.barbado@xxxxxxxxx>
- Date: Mon, 8 Jan 2007 11:28:03 -0200
On 1/3/07, Jim Manico <jim@xxxxxxxxxx> wrote:
I'm most worried about the CSRF vector.
how come?
this is client-side stuff.
--
Marcio Barbado, Jr.
==============
==============
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Follow-Ups:
- References:
- [Full-disclosure] Universal XSS with PDF files: highly dangerous
- From: pdp (architect)
- Re: [Full-disclosure] [WEB SECURITY] Universal XSS with PDF files: highly dangerous
- From: Jean-Jacques Halans
- Re: [Full-disclosure] [WEB SECURITY] Universal XSS with PDF files: highly dangerous
- From: Jim Manico
- [Full-disclosure] Universal XSS with PDF files: highly dangerous
- Prev by Date: [Full-disclosure] TK53 Advisory #1: CenterICQ remote DoS buffer overflow in LiveJournal handling
- Next by Date: Re: [Full-disclosure] Perforce client: security hole by design
- Previous by thread: Re: [Full-disclosure] [WEB SECURITY] Universal XSS with PDF files: highly dangerous
- Next by thread: Re: [Full-disclosure] [WEB SECURITY] Universal XSS with PDF files: highly dangerous
- Index(es):
Relevant Pages
|