logo

MIME Sniffing: feature or vulnerability?

ID: 4feb7ff6-4ee9-5643-a3fa-5536210421bd

STIX ID: report--4feb7ff6-4ee9-5643-a3fa-5536210421bd

Feed Name: Fox-IT blog

Threat Score
35/100

Date Published: 2012-05-08

Date Updated: 2026-05-05

Author: Fox It

...
...

This post describes a penetration-test finding where Internet Explorer's MIME sniffing rendered uploaded .zip/.csv files containing HTML/JavaScript as executable HTML, enabling persistent XSS; it explains how IIS's application/x-zip-compressed MIME type triggers IE's detection, contrasts behavior with Apache, and provides mitigations (X-Content-Type-Options: nosniff, Content-Disposition: attachment, whitelisting extensions, storing uploads outside web root, filename randomization) and recommendations for developers, administrators, and Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.