Web Hacking Members Only

DOM Clobbering & Mutation XSS

Two bug classes that slip past sanitizers without ever using a script tag. DOM clobbering shadows JavaScript globals via named HTML elements; mXSS exploits browser HTML-parser quirks where the same bytes parse into different DOM depending on context.

Related Articles