logo

Practical Example Of CsSQLi Using (Google) Gears Via XSS

ID: 792dd216-aac4-58e8-bf76-b803a9594d51

STIX ID: report--792dd216-aac4-58e8-bf76-b803a9594d51

Feed Name: Zscaler Security Research Blog

Threat Score
30/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report explains how persistent browser storage technologies (Google Gears and HTML5 Database Storage) can be abused via existing XSS vulnerabilities to perform client-side SQL injection (csSQLi), demonstrated with a proof-of-concept against Paymo.biz; it warns that although the storage APIs themselves are not insecure, implementing them on sites with XSS exposes local SQLite-backed databases to confidentiality and integrity compromises and recommends securing applications before enabling offline storage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.