Practical Example Of CsSQLi Using (Google) Gears Via XSS
ID: 792dd216-aac4-58e8-bf76-b803a9594d51
STIX ID: report--792dd216-aac4-58e8-bf76-b803a9594d51
Feed Name: Zscaler Security Research Blog
This report explains how persistent browser storage technologies (Google Gears and HTML5 Database Storage) can be abused via existing XSS vulnerabilities to perform client-side SQL injection (csSQLi), demonstrated with a proof-of-concept against Paymo.biz; it warns that although the storage APIs themselves are not insecure, implementing them on sites with XSS exposes local SQLite-backed databases to confidentiality and integrity compromises and recommends securing applications before enabling offline storage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
