css-expression

1 article
sort: new top best
clear filter
0 6/10

A reflected XSS vulnerability discovered in eBay's search parameter (LH_SpecificSeller) that bypassed character filters (<, >, comma) by leveraging CSS expression payloads in Internet Explorer. The exploit worked despite the vulnerable code being inside a display:none span by using style="xss:expression()" to execute arbitrary JavaScript.

eBay Sukhmeet Singh Internet Explorer
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details