logo

Google Docs XSS – no bounty today

ID: ead8b9db-b3c9-5b05-a92b-a03eaa87617c

STIX ID: report--ead8b9db-b3c9-5b05-a92b-a03eaa87617c

Feed Name: SensePost Blog

Threat Score
35/100

Date Published: 2013-03-04

Date Updated: 2026-04-29

...
...

The blog details a ZIP filename-based XSS vulnerability in Google Docs/googleusercontent: by placing a harmless filename in the ZIP local file header and a malicious HTML payload in the central directory entry, Google displays unsanitized content from the archive, enabling phishing or session-theft attacks; the issue was reported to Google, which deemed the googleusercontent.com domain a sandbox and did not issue a bounty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.