Google image search

On September 12th, 2015, a bug bounty hunter called Mahmoud Gamal discovered a reflected XSS in Google image search.

He discovered that when a user opens an image in Google with the option Open in new tab, Google launched a link with a vulnerable parameter, imgurl. An example of the link generated by Google is the next line:

Mahmoud Gamal injected the code directly into the imgurl parameter, like this:

As he explained in the report, the exploitation of the XSS was strange. When the string was injected, the XSS was not launched. But if the user pressed the tab, after a little period of time, the browser executed the XSS:

If you want to read the complete report, you can find the original post here:

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.