Previous Entry Share Next Entry
01:25 pm, 3 Jan 07

universal pdf xss

Reportedly, any site hosting a PDF has an XSS exploit. The link has example XSS on Google, Microsoft, Bank of America(!), and others.

I anticipate a great flushing sound as every site removes all of their PDFs.

Update: it occurs to me that you could probably also fix this with a mod_rewrite (or equivalent) rule that 403's all parameters to PDF urls. Update2: supersat points out that won't work.

[via halkeye]