Paid Advertising
web application security lab

Google’s 404 script was vulnerable to UTF-7

This is interesting, not because Google is vulnerable again, but because it is a pretty common mistake. Default 404 under IE doesn’t show the page, but if the server creates it’s own custom 404 page, that can be problimatic if the developers don’t know how to strip out XSS.

Respond here or Discuss On the Forums