Google Blogoscoped

Forum

Google Docs XSS Vulnerability

Philipp Lenssen [PersonRank 10]

Monday, June 18, 2007
17 years ago2,865 views

Is this potential Google cookie stealer fixed now? I couldn't reproduce creating that snippet in Google Docs:
http://ha.ckers.org/blog/20070617/another-google-xss-in-google-documents/

Tony Ruscoe [PersonRank 10]

17 years ago #

I couldn't get Google Docs to insert a textarea at all. Other form elements, like text input fields, still work fine though. So, I'm guessing that their quick fix was to disable textareas altogether.

Ludwik Trammer [PersonRank 10]

17 years ago #

His demo still works, though...

Forum home

Advertisement

 
Blog  |  Forum     more >> Archive | Feed | Google's blogs | About
Advertisement

 

This site unofficially covers Google™ and more with some rights reserved. Join our forum!