From 3da41487e5767ec1219f6c9da7f56c6ee7aae0ef Mon Sep 17 00:00:00 2001 From: Mohammad Reza Omrani <38619429+omranisecurity@users.noreply.github.com> Date: Mon, 11 Dec 2023 20:58:08 +0330 Subject: [PATCH] Create XSS_in_Converting_File_Content_to_Text (#846) --- ...XSS_in_Converting_File_Content_to_Text.png | Bin 0 -> 18437 bytes .../XSS_in_Converting_File_Content_to_Text.md | 26 ++++++++++++++++++ 2 files changed, 26 insertions(+) create mode 100644 assets/images/XSS_in_Converting_File_Content_to_Text.png create mode 100644 pages/attacks/XSS_in_Converting_File_Content_to_Text.md diff --git a/assets/images/XSS_in_Converting_File_Content_to_Text.png b/assets/images/XSS_in_Converting_File_Content_to_Text.png new file mode 100644 index 0000000000000000000000000000000000000000..efff387d7456982f37a9dd358ecda778ee34db39 GIT binary patch literal 18437 zcmbrFWl$YK+otCn+@0V~aCav_aDqc{OK?B99s&W9-~{*J?h^C_5ALqP-QAY=+pVqI zzwcJ{R8LpURCia;R6oys-Th7NgB%7b2`T^p7z*+-8UO%(y#)ivaIaNY0bT!V1%hbE zNrC47vIf33P@LuUAOL`d_n!*{q^1)A034vEto8oo<>l$=siUK#udna*K@JX%uC6Xa zL&NFm>64QaJ3G6HiHYp&?7+al-rim(C#SHmu+7a)Gc&W&(o#Y~LJ0|p>gs9`2!xD` zyt}(AFE8)w>zk94^Y-oA$H&L#=jS(X-ptO)!N!RA|hgMZ?CGV3KbPKIy!oNeSK|h?d#XCBqSu<+}u`HR(yPX zpFe*d85xOlqyzkj#3w(jokJUuURi&kqg` z`uqE*rlx{|f`o;IcXoCrCnpaN5BK-?2L}glZ*RxP$45s;H#RmN9v!oq@sgX8GvsHv&>?%g{hBO^FCxRjI>S65d$I=ZB! zBnu0R+5TDbaX5%EDQ_` zVq#)xX=!$L_N%L_xVSiMY-|q?kM8bnMMXt-cXtE?1ZHMtdU|>k6cipF9y~leOH0d7 zpFWwInmRi>OG--W>gw|I^9u+8$O$-!VSPEJk;1Y&G#TvSvfBO|l0un-aw z(%#;#tgLKcV33fIz`($enVDH%U*Fi+*wWHcSy?$WH00;!m!6*P;NY;ly!_|SA4*C} zYHI4NtgQF%-vrvt)-%(N=r*?ZEXz*2oM(+CnqPDl9KxM>sM%KXl`!q{QNux z1qCiHZgFw(j~_q${rzoiZOO>Unwpx_UEWIrfJ~->%sVZw^rH;#^bgaNeWRk{*A(g$ zJPqExI?@fj?8Fh(99)RO)}MZG$-hl4 zR6)!1 zO`gi}{r2-%Lr;X>I}y@+`gcd#pGl*oG3@#CI~UwJtNMML#%^oGm&ck5q~W_tq-;f6LSea5be)v@R&G_y zIp6f(KZ=$ZRRh~taJIbMBk6fl;MTH}PJEb@Xtuxu zo0QjHPirp@l`BnRYpomi0CT+{PO^4JTOMP@9dj759cQu@Qa0t9s%#U1i|WvN6AYx@i5i)8qnOR*d6c@nMaOB~xXaCuPq9+d#WfP;#8=__j#V zcDpx{$3eal;D5Ot?9-zOQ2U<$0456eE?nl)8;gxcp8`Ql*w6LlOd=Vr2r`Ew{CMlHRTwE%OXY0YFyY`4(cV# z{(FOxt~aCG^BWgU5q$MJQw!911nX@kC>a)=#nfO@2NO2$Rn`M4*8~6lRrb~5JB4{& zqIF@v6u^?`;l?`(&@?8M^`;xexPgmoIw;7E9!P;x9HrsK(>p!+6UUh}W}@xg9^IK0PxWG*u~Xcy9EX&yEL`c6u4KU(3+L$bG0@J|)1 zsIyOBvo1sV;=Gqh&{$7M31f~TE(&<7##=5XFY!AzovLgOTj*NhpjtHOXI26;7rY}V z9p057&o6MuYCswYAlfKPd#Jeq3QvEys|InnQxFrKs1%lHWVvq7hf4*_adtnIXl)5> z@E6bmTBzFZXrZgt5ZpxGvMf1*lU+rI5M>uf*?*#P>LHC9wkcSgjHtUy_pTs84~s`z zDj$Lq(czpYrD%PhbkK<4Kbw<-iW`7D_pV$DwH@^wTarT@QmWxQrsqToMh2z&uKXkh zxvC>X-L1W|=;1VdL{C+=RFDIZgfNvB7HT-hc7Xq%B%a-J=wtD-*-Nh7odhxs zG%z@g1E^my?$du-ewHnfwmWPnt(1d5b#g|7cdo?-A%CIzuZnZ!S?@&Y>0PVE-wc*n z?IyYB(ainHb-SZ~Li?7#?v}SjvfhyGqsfuf6IQj#ac^LiU28CJ-pFd&py87H!w^>9FA9~gyHev2k>*9Y~h1%a7Ar~CUZjy zjw)#bO0}X_q~k$p>YTlp;f|L!leS2NuHro6MALvpF{*>#NJ@!0!OtFE3~hb`xCL|% zU9~Dbu?;l?1D5<$EuAa-DfOV8%k~)4$*8FYQlWb%OT$HqhVv(QX5Uf#- z){Ibvu{uT!sjF3n9I>p6jym=f08;u|tur1i0-PDreYUH~DMe>1pGc?&r!^wwzQW;1 zKw@FhR-iZMGoS@MtEc(MNZCF@iyJK8mPtk_jNfbsr=DaUv#rc51~KAgTkw7l?})FX z_Or3X#Diz7#D;M1@$(O&E&}9?WHja~ZYzr>I~IoLjBhaTAUwyJyGE7pivwP~LSS3p6DgZrVO{aL2RGCJm^4;1w(r|PB0ItVWsbF`#`+#x{4)Sv)Y74w2Nd(%v zS&wI;R^e)P$=9c0s4mV8XwzqLZl+shFMS&w1qmSXAB%V5*RObT_F zT-_z}_rHqny;4S-+Km9aS}M5Sb%C8~d5*xTW2hv!@1;P2wRq1mk}sP) zF9&Y;Jq6-V)B{V3Av7&B&}LTLyc1E;=nOdA$W))=gE`(lcer>bX(Es*+v@(|+p=I@ z)@6^41oz3~ea`NMu6?5~BG!&t641L}zOn#K@U@QDn65HDIou(XtVZBXq@1)o3Gn** zW^4XxGJb~aO>*pl7jklW<906ZL!?;glgz3W+?V&E^JHkyzFqOeqen>!FCVIny}dtu zi6Uec_2lJ*z-Nyh_jmpT{87X&b#+134U#l%ofEo zWQD{E)rs{}9jHlUJstleIADtO=Xo*1Qot`O zZ+OP?Xu}XJjv~#4T?dYA)@VRqw)F6=O8LG28$I`r;N8uN2GM9Bls4;kOh@tHw(h8HZh0=052?=P6^JaN#R zoiQ)8jo|_c6<_p@g!rkI*`Sfz&Jv%2w{?66UK8YmyP+L|!H(D1S0-Immj!qO7Ymb4Xts)!0QaHH z`ro);&WVP8&^m%{xBIv}>nXq=hm>#$MdxVU~Q?^Lcd6<54MK&o|ltU zsUD%^lVpC4e#n>d#EL(=9_(nZwrm~zD+83Q=u!AFl)Io%9ip2f3WicQ2P*+3({EGH ze7}SjtR^wO^jsQlO@`HG2pDI9*OmOB#N|AAlGQ}nhO_up>-9`P zW#jJ9{!ZH!Ju65M>1;Ugj}tg+Hl?74B>%Y=NuUzp#FZNls*!6_HWg(x0XIB>kR^f8 zt!%!i_S$LRMj@UxNyem+Rry0BLl((JQ6@(LA=LKa$t~+InrEsL_$u~Cg@SkS`DFaS z;X}|xZ3IGgKmi$@iy0&u2YNo0-xXIXkqtps0+?4_slJ?#e-^F18)Ac2YIEX3EY*I; zU`kh09eS*GVPF%7)feB0M#nYo=p6GOV%=nKR@m1GC3G0f|41xu$O>1wQ&qXENJ|GH z6Qw2mx_+En^k)$WIkCFdda+!ZeBL=~PH2f3AUmsWi90!J$60T1;l1s+36=S8vgME$ zTvB_|3PbrOPZw(z%=PUFR^1AgH|I}(jmIDlZKO{hOn(@vj<4F!bG$5V`aDb$r)!Rh zh@bXW+-DVT^6U%9WlcSN2XsAr?{WI36$X9#)s?0(Z_GAgn4^?z7i(uB3_O=Rdlws* zpXIhMl13&!3;Gz1=EDozF%;>JF<-SS!^d=)mC(D1w(E2>wG(8>6(8Q)oe7uqtOwZtz-cY zOl|vFy)v_XxS-#5DUE5t!$x4cl;g!n2mEWPU<^nM%>BrSfp=+jNsxNTk|#n?VBvBc z2Jzn4Lo{-)ZIYNLof~NC3`jHE&{(y!NK#wHbVrXKS4%6e*MJlAos|X%f<=ft4{@Qj zid8nieP}s1f%QHi?4u#KowfMN<4-^0hBrJ2oaYmGGX$=S_K(_zCTR``PnZqrns@g6 z*VSbo3lsWo;xIr{++w;SW6Lu(4rDeq$fm((cDxK%RwpdPI8S zwRSv_Kfc}g^19cC;o7L~3Ac*BDU^#=0X2(t8pLxp&MP~adQ!M|zw;d>Vj7k8i2J@b za+HBrFsX&g>~c>ao$wHmGjm!FTP44K_?X6raKIvpUp6HYK4C(`j`kw2eZv;mK>P`5 zU;y^F>;3YFcLQutj7rCUBALT)xeI{(j)BkuoUY#=@k=TWzT-JLB1MUiAtmV2JaaKy zQ+(D#x%?Nvji83jWMSWXTp1Mgz1&s9wdh!$2H^p-6W1ic7o{(XSXJ*oE6I{LvARzb zTQ1D^*VZA(DgqeZIQwFzNN_*sW>H53!&%$2`YohWE3J@zQy5*~QSp%EA{3@0H&EDD z07q*W*5EAngyGeZ_YvS@AgPXDCVFe8k-id6=`YLCwVK`LZ}V9*V8M&G9Jr=&+^Svy zb+!J4Ah+&_Nf0k2{}aDJohufu3W9S<>^%RC63!xKPWbDAX_~?-sQg#&$KQ+U?p&4k zlg6?Bc^b`Rix_^DtRVPd$$#^PbZE_asb7z$h8QeKJf9@$DLFHHJu04cOF4rP#UHq@ z?%pW6>k|dPE4_rP`sv%I%8kn6ehFTrv}NNZj!wa{;;?$=Owa)|S#kv3IKl+hP25WSqIMK8gyZN2vv6}3&%ioClBrU7iW z6{+DI{b0$?Kk5F)`F#r2fLghv+TtHr&@GMJ=rphhCRgYsyFdFAkHg0u37}TL%d?eI zz2A_x)NI0Aw=N`sH^nzGqj)?hQMYGQz>xVn?}whf-mq?X=utC`XRJ3X?TrjG-+)Z% z8PDTT*q~&KdQ?>xk%M?~O@M7HG?yI!i{@PxKQ|~)SIindhY$J2KB~ZXkm{L(WFYul zvr>dJVq;JaHktQTY)S^`%g?M};I9XqpTpiB);DVtgRPwrHRnxf<<340iI{zKAi`N= z@L(fJHf>6p31nw6*V+CpMD7#mB^*W)fvA{L8o8F6YZEMU9g<@A@mq;i%&$7&Hj4Bf zWZ-pzdmZtBhN3Sj*Ln7y1jO2zBXF5`;WRbI!csh;yPmtVB&umJd^D6; z$IMHSs|OTL(7i3TL7L)1aOOo^-Sg*}r`QL_xvMq8pCY5n^^5n8<)2jG$1EgH-Hq0c zEPV?F}Srx`Cnr!Gz(t;We+Jx%dt*_~nqVMFW9py;tCzQ&dRDSpdTz`IzwdjX>Yk|UeZOq0Eh zN7HV)FbnZHWLdN|j5Q8_bN3H7mMO=OMBqNIK{+a*$AW35p6gR!&IlfeO@{mXy?t3ajmq^&%NdmVwkN?YHm`3;br%(+`)agn z*T}FgAztSwK8c2*j#7g}+cvd$gx8E&)ErgP_c}JbV`8u*{5%;SqZgYHD8wu=t8)wm z=N4@jWlf_tT1~R-3(68Ph(c2o+akH}L7izn_rh)6w19|a@pB@?8tY(Nx<4|pw;K`VY;tXNg9y2xyIy}-zyP5+}?1-EDwP? z9oS^8#&73H%^-7zz&#pHD$U?ZdbaU(@*4XkZP@AB!51lv8ly;#zDZ3R4JtW5UX>>! zfRFc_s#{J5c&Q8Jp1pC3sD_t>>{|cKpYqQ-7?}EckLr%+qFz0^IFg!f9WfJC z_cjqY|2UFU5n{?BdupCx092n@uRj}6fUSoHmlmwr+iiT~$%A)KJd=-^vnDCu59*KP zz^2wkxRrFV97 zOx)_eJXAq;O$1lvip|qr^JS%4Xv5D>K36SrfHMD=g(ERv5iK%!%5yytve<%ZGysI$8RpE2PNFfPd2r7 zMZ6&A{77m0B33lNa`uJXc^v|Sk94Xd5KLQH_o@yoy3?zBP@?U41Vl|9A zL_k^1fRO^QqjB19)uw00qmKcy7#tJBZyOl7)4esrcJE$15M69B5A6Gb1`*z;JF|t) z-ajTMl?do>>`e>N2!oyxXwgIizu!b55sH>toIMM8GFT0_4|z#XjB}X<<>uZ|Z2EVt zq{t3sXqMi2iud;L5JG)ih3U6?4!j}&-fEMk`NC}rVc%N#Z2pM+s9e1R2vLDnG^!C? z(cX@PT!+-Olvnde4n!?75bo+;K+Z2hjURu-y|caagHP$Rgzj$^6iK6rh62K#x#pkA z=O4+it8J5f^=TeSBb2+Fr+inqRP0{p&r?q%Ll(PBZSGs#4c%JMzpvm9AyX}}lN?tU zlAOI+G`SbxptM=tXmw@!@9~joW=)`TJ`MfhwcTaY_o0N+k?EfYrj1CSy_}6I3^ln$ zt=Ii#Ge;pU$!#0ch98})r`8Hr^(LEXestw@ zh?0qnpCjW{M73xD_2ifq%BUiyKIm@skI2HQ75tsruDYn%ghMA1C*3j}xxcI@wVPzP z9i#DPmyt!n*gplvGyS43*5Z=KAT54 zEkC#*x(v09GkDp+o|?0n*pG^;~-25y24jFogpR>d=EvTj2gf_YOET8kGU zxZJ&4WX;&|E!4IG^<2L1?6Z$mnUT5>sz>4Xf6%WpcGJH8^0ZmEZ%0zKtJ3su<7B94 z~)rKghwU)52X4Veoj;cwqD;46>`Z z=BLUry+iGMzeM~d6J3jX70O1mDtFGIsTGepX6ef||KUA??7C`g9N`p`%G6JjI4&tP zAb#P}%SlA78yCPJG+<$=te;lm6$tg8<#gU~Yy$yFzK_c1|S*3jX*kl^|P7*m`_sy>XCT`S;==njw8dY?;mM zfwWyCw~f-~DW1qka(A;E*;rS)sdSn%Q7-6#pcITLH@dOK_!TatSD z>`?RXN(|zUAcDgI+s)&?Nma0%T?YjlG@H)PY-QY^6-ty*_VGVL&OK?J9?(1DR0t z!Kt)@(GV_-W3Frtv<;TnEdcP#1VA|*=(wP~A7Kzili!W#TN$@|6)w&~pF&mg_9Q1?lJ164v8 z;vm^&^ptpkKJe0H^lo)rAzOSD7slOCkr5a1NcK*nYT=9)-gy@byhXfSB4}U5ni0J5&4?RS*drf-gJ4%0T#c#dtSx_UN zBnaWvB0HTuQ&HFt;eDfSVp`aHLYRJOSWDhD*EHB#nVGwsHrkLK8aRg_+Fg#bq+5Vu(qJ5BBaquKJxSlKM{gt@5hibVza1-TnxI6Uf=sh0(>-fQg3n1CH+3OYyy%zA<3i8+73Vm|c zDEeSEZF%9+H!Sr%N4xf@R1-)i%iY^JqQ&bUKquJNIvUJZnZZSG+5H>AJLXr$b%nIY z8Gk6y73z;#NDLe&%a=C%2Gws$MI4O@uH)N&?OY2z^enow+z4jn16bOvu0rd^^q*B8Tt!6?mcHvvthdU4XTWzS;N z_bREGg!p1Nlj#AO@m&dq6A}tT^g!LbW*vL9U0PvQ2S6`VyPJ?iIL_V68Trr23J8c z|B9WG(VRd?L*Ug))nr@p^6~pTdk*zJgxYPaR#T?F5Jb{lL9lI<@y%) zl15~Jd9o;6pL}!lg_0#AxzabRJP{^8N#Gm$)66ggD5*|RMIpJKfstBL&^{fCL4j?O zYIx_3r5M1G{>H-R9*G+VCMOwgT>Ra80ACVcku*y90Rt3r-x8WeN(hLAHB3fjAJ~%@ z?F&{oiPyeC2(iWU(0Yb&Km8@czDX`!LyHFZ0-`-}FMtmNaL z72ylXKfj8e4*VNxbKhBgK36|SDiYMq-`4hv+1A%8hnYhftHpmFX!~}Ul}+{~hE;qt zNT`}OA662MJ`@PF(+5orYb!*(Xxr;GIQV!Ssm`PR7`eX!vvq)*B6!eeD}1*T<6#;;nHi~=@JDUSO@=D{pSnnH zlt3d~A9+-8K9{1C#MkZuW^iAPTYjw_i6zAWg(B#euYjt%ixTiswS)F@?1R+}LR)dU z7ay8QQ2LD{J(yV_@+Frmi_=wxyXx+*w)|$fJ{G-3##h11LR`r?_GUt`&Ik2!Xk?(H zEL^^ErfN&GyDFcW9vB(Ucylp;F?68JxJ#!_R`wF3p){Sq_PqZAHTqcS&G|k;RH7V& zeypCs1btJojn>U$;^TFvNa1bV{QU=bjfROywb^Po(3IM?^wi^=OgooI=>R^g{{ipz zV)1Zx65H$38SY#&7Fb`H%x=yp$0!usGrZWYQq0$ zq|0OQ?;-A6){JHPJ(gwCwxUdisiZ@F?pG@eb$R)qr!M_rM`_fFKG+Lu?rb*sQ}?FM z;My=n-3N(QSsKaV90-*DvPmMCXLX8*boqzROf%p7*tTc4Cnke771XCp{5EiMFD4Z*N3Ioaob(RoefLSH_(O+I($ z)Xryy)Lo@(I9Y&3b;5!X#^^vCYCo<0m-qRfl8s^~x|3}r3t;9GZk$rUe&#MBSi=%LCbPPr~|ze4TH2aRrDHtCN5^6gr9 zr2%kTQ;fR2HyW^1fvvV@(L4(d97~?5!p1cOdl7~eAy%HOzbOIFbC>I(cw(N?>a-k> z%Y$=!o62IO>v^{CJ!!-OZohk4n#uhreNJvEguK!m(M%t5^PSJQl1%{xQjhb9m$vYy zg3aF5(Hn1jz~QrJ9azrl?lLt|{~WNBGH0Pm0GhWQ7H51?wAcN#RgVcXD@yc1q!25V zQfLg@0cS0(xw)cWzwcx2%I){SSFO)F*+n`T%(>fx`8{h*uw1+V$s`zIw^9ptg|es- z@jSYQ3e-BNlmx8Iwupd94Z$C+h}m)M7^hOebEfyTLY}Z*a8owd`=W7#TkCDm{$`zOY8>i-tQ3^jYLFL+PNiZlHEd;d++d=UqWij}&>Fu8;r zt+TzI-4tJ3idohO=W>}OpiVu`N2)RzjLbU49nQ|%I;$6EQQ*kN1}%ij-V5O8KjbY6 z7L3-xpK|piXl>?sT_)GNfH+uol8=g)$1@PN4cmbKnb#$EU>r37u^;|Q{D@3++%{cz zVS+dbBbk~fXuFCh{<9uStSs!)>##ppnD`mTXU@G{3AmrF1R8QKPH8 z1RM>FHXkT&nZ0iv@-}F+Zx(RV-Z)EfFZ#($pb=s3bfBupR7xuSn4#n%HSGQ~d_riGdfmnl;5fHt#>?!M-v zAuD}bRKV}y>N@`#VdV7mDJgLoJl4@ty?3wwg)*mk#fv4mxA;9BPzhXI>3R^t(ik^N zE^16Xx{t&1zOaLoJ=6NPYS~ZtNqFGb!r1NL<~O5!%QyzqIlU4r+hBd7hxmLMEWsTL zQtCSjVy$UJAwcG+|>chsWip|)RGCOe|EjlH&aUZ1u@&9j7 ztVKdWhBObhWTPlA7F+P?(jjZO4XNvx2^&<->w9x=$(Mjj=lUqpjdzDI&bDa8L1c~h ziD*mL?*fX9!#n~6@)Ud;W4-|^K!9h-m_Hd>s7br)gV&f_-nc?XM zFyvoeHg3=Ck`^gmsv0Lm0Wto0sD=nfpFB|hVzkc0SqEzG`?GpWHHIqzwv_)&ex*mmD3E8z3xl-M;}+JJ{XGilQ=?FjJFB%4Ul_FmF1<{n~1DESLQdCf-P%XrAWU z*!`odo9;^v{~0v~7L2nF<<3PIz0lD!76Ev4!(nS^f<1(JOST8rB_izw5`Gi)kRchs zScy@f0Dml*dWuPrWo64`azj-lmD40!I6m-$k-@RGGSLB1G`AT$s3?gMhV@JTL*b6s zrx0kP4ZnZ~&vYf_yot?M6KL#E)!%hhgO({2sO#CM0C(*dP3DYg(r*WoI53k_<2aeC z(>gKIM&*Hih^VRN{fU@nhmNg1O7=4y)$eUkVv+$M_SQM2E4?MaZYgK>6N|G$edbwT zRl-CQzC}#C%fuVlfcOt=@!Zz40H!{`^iQ8zD4?ZkTT)yR2wLDwbj=lQ)tO6Aj|En2 zLFHa^$PuHL1Oa{Wq&!JTCRmH+pFp;3EOd6)>W`W8*0G) z{Ds0rhfRSfd^U+@V6^QZ-oMEiwt%s(lwVTbm-!Yj4dg2JWJ+ba8C({O5j<2p<^5q* ze%qNoxrC};kU_ajg#YZ6IsC~n??H`Uf#cfn8^&ox(w`j47}(vr*@{{9qiNS+a5!rZ z-X{pIn-cu#0JBdBQafgPQ%Ze>YR70rG&;Pqzi3Pj!nN|#hq7ocofVo2y;tI^F_Z1i z0xww`d4}15-jOo0#%BpGTb*VopkSMI6w$JcacWwegD`z9iwnkDF-I_(^=pFh;?W z%vPs`D&bIIimOWLxQ!K1-5G-@_VDwd6OsHszB$nm)FGq6y4rp-JGr!acE%(H5#q@w`lfqFVjSQ!+nsxg()z7YW zRqdV9f9x0W^KX8B4a_Sspp6eOg6}*@Zt)dj?=S5oJNKgfAwonpfXkBd4$C&Awl)F8ib_~+?8aNqXqMK+Dga$@Xoq~7EwsNC6X zjMstZel#WY`8;4QdSN--J6k)7R=OQCI-vk}u~b?Iz*Caswt{3^Y@`dWi`$GIPam2BJ>om4Hc^&ShXSYDe#t&Zb#}Mhzy`YPTluzZ|PHtS3VjPvE z(z=X4ZY8_q`J(r9$w;EfSfN857ps^>7N~31=N6? z7MMm4Fxe~reL8+@6Y2b}*gG+H2yj!Sg%-{i>@n;|&q#V6?aqD8Y+~O%YM1h-)cI)T z_u>Bl<;;KBF#^F^+pOH?aa~-LAMH^84^ZZZrhgWue)Z2C@b8hEHmkeI)FhlAD?CKe z9j=}EN&$O9VNqiS8_Lwm7NB&lmeP0wV7grS4n%RalS)_{oeU-_Yoy@$sz#traf}np z6@mauta`=6nEhb}aqzzabn2JcQ!9%$wll^EENilyJii0$)b{(9)e&+)W=`pI;+rD7 zINXJK=BrvJXxA}b$0m+s+EX*U8a!UPW+TYQ8QH}jiUenxnv~wgS+UF3*jw2aatc0lvL?7Bixn;%!;k z0<8p3PbwEvJkzATy*WjdSLs&4uQ*cv`_U-NXPovKR!#L$aFaY=shtsjvk6tUz0uK% z9SRkZ*NCV~um*|^yc(b|Q|t?fZJkcHJEZ>09AT;-M53~bm2@AC=@sH72l-(J1{ir< zzWQdpmxUz1zOv8K@ChLp4!<=-mK1K6ND1I&h?dpkTh7h7p&9Q7;nu6%Fr^nM1hQTXwnCZDj_b=jllzjFzrJJE^EcUB|CheLI> zx-x#os}+e+3eriw6OcRuKl!1fm`c+SM!4VR=riv8IL$PC zOO{dm!_&w39ba}z%E&<42po9Z-J>wm{uy!e|YF#qkPxbb(8&ih%MjC zNMDmzFIbII1u5>wEJ$K*rgSX;P2ge5Pq|~U4t~v5)PICm)N;Q=@m|?*&(*&56Mt`D zX3j@!kCu~l9WHJh2X5i(#@L$YuxbhAi_+ZBxm*t(tAEQkv_*gZi47+5xGa!e1(1LML+La%U=|XapKZMAE4HJy8ZLewnsg z+xy-#lX>yv2`QF@INEqv(m*pXHQ5}nA(woOi+wiJSnBrZ8suV`o`L_Kw$&)aJbju` zmmUo3foI9vgdA_7xhHs&B!aGAJe;UlN z#{1W1dS~pAIhAfbitzTBDUx%4vmbx1C3a-Xu)n80Fk`9Fy4J|_LWY$pCNlTFO9H@< z!`T)05+vVXVLJgglnrUa;WdDdHpL zSZ{K?dRH%HxOg`rDSa6A(t2{~)b|7s^oH)J_!ocKB`8jAxo`@9lKR7)1xI~=Hh565-e%xC8IkgILT;#T0H^hI!;MTlp77hjS4!-*0=SWJCH&EIppuUXN!k z@cd%Hg_}eLh@RgOmwd{+#`iiw2-L4E$n{pjU+wR(xEG!-`OI5&C+**<;E`~?H_fXJ zNd{Y!RY?2@0N-lgJts;b#BcMfU)eb$>z`WMnyqdvSvj3&w*9W34i8w%VYGeI@RVln z9ezJ%u~s-cQd<8_QcIo4(cz$I5jUz2ZZsc9QjU&|Y+*65*2$N}{UBfJaBynJ#F`X_ zz(To;C|bk{syq7=!qtYmhF69#_M@cIT=vm&pQfhy_!^Qo2B|Rj?(i93agJ~LA@s< zM(1G(fdNLTfbewe%Bf>v`j&Gxr5NUW!mkB5FzGe7>HwZCYT!+ms>WFVZ+)x{eZY9K zS~L+ccBSRO(j%>h3CCy@OtXciZy*wlSN-ia~0jZ6ZWki-&vJ!0^8!D42OXH!=coK3jOje*QD zIdOoE$yAU3{z{vItIcs@f}LdkPt-U*9nu!pwZoSUietY5k^(&zX+0qRve$w!mlY%$ zx;L=&+o0`-U{au@Ehs%N#=uQgJc0d6VpX7TeGWrV1@s6X*mZRVCaeVp_RSLkM7sy8 zf_0f8zL}a|feZR(_ZpazHut1j?kr;C?_eRFNyp=`vkWK4-eqNOf~WGrL2l`!ksfn z>`-9>IQTo$v-SwWW|6iILO$2-31vrC!@F(Dpdk;{^VxkmwWM13Q+}OPt9I)se8q(E z3z!yAdU>u%C>f<^>CaVX)sAU)NM}7Hh*}GHG_j{-w>LP}M9KLN?~eJjU5^9$Z7|w} zA7R!Gnx%GjQ!U>v3f>hBjJlk#OpTFdf^SzyK(eOTE$uA@>anoKRznaQkiWn6L^{qg zqBq>S=pOr?@dgKDh67|)06d4$4c@rWiHMQVR?tJ|6W`m+y=`@x!O2I0sHSgUO}oAZ zJobTg?HV1)U@rs8`NCSve2*LwRcfEKq@jZLYDd?EmiDn}WXYd4vDNE^wx{D8dW*BU zF)u6i!`^>}K!gXEuNH~1Zuzi3{f|Gl)kkhq+5co7aS{C~eP9KtWhO;vSL=+1sp`18c&ygDH3HfIBS*~6pVC!MD6xZI5v1YSL$ci&$ zl>F;bpmePW86|;t%H7$e83r5Y&N!roNKF2gCvKI3gJpel1PLasDN8i31@m2aBd^JM zd8$2qq*%XS4QRD&8hW^=<~lMItp_kosWE_#Fe_H*HW#CR$i(;gwsdB4MQ=@a)qTUJ zu~W$>n#Znw^*~{FQun4~#P*H#A*=t@$(8>z-N5nh)-buF4Y^*3=GLJ(#tIQ~J&0U$ z=a`0sA*cvvQ?R9@hdqLwBob6q{=8+r+a zo?SpsycS}$519joq!v3xS2I5R8Fp3EwJ!~NZG9+fZ9*Jkhgwl$eya}+EQY>f4BWUg zf;BhVa_5>1YUH}XHRgt!D(N`2I`!cJX2!|z7ORB-#lp+P;pA5{pAHhj*7}t@2u^0a z$o*P}-C|k=m9sPwJZmk>jal^QoL`%q)u{BR1Q;k`3Ns{ZEmJNN@y!`?t!L&pHZ$htVNA4NQ zH8_xzh9fmU7qV<(C=o;51^hnE<39Whc2dUUG43A*jOmZrRO~V&U`Z(H0Q>EmTxjFZ zgC-|qXj>DllKOww!eW{YIeF3?Rwk8|v6T3cw?(szmNHzdlwCGAPD|PWBcYq-$=HRj zh{I%jKM$t5w&<+SH9vGyxB_Ia$Lw~x7~32Q2A^+#$XcDotM(gLR!1MVt+Kcj(Heb% z+~9Eg!rt~oO`R;w;gn^~Z0{O^hge`afF1LL5`FgvYyVV87u=Yt zJyDGcFF9kIJa+stb9BdF)RK#+s!ykiCd3;RkLN*g>i(vsY8>v)jXziY$jpvuP+f8> z483fzEJS{jV!FC>AK&Km%sLJ#9f8C<9?%6i zIe#;24D5dUBKC1C1o21<_}$$K!TccfE!|+#p48SFD11*BxJ!HP?RzfA^?G`8HSRrT zVBhh50`;qlA7FGuvlXW3C?5;Hc4+XH{@oQP=n7PPn~YLDLV)<_@Z>a zWKV7Cp1eB!y!6zS9oUMJ^LrrJ`?}0z2;v_=i2kLlB>{pY^?QKlYvjFrPQSk5e@RwM zRAtw3qIxiCTuEX|^l+>&rYT@7z1}2n$hi{8^-G_vargaQ;0E9usxtg&PX@*%9*Ixt zKRZ^Ck_p6V%z4Vf{YHKj-VaRx0iIc;HDji>1Q zB!_U;8b4*4B`pFZx6#2Dn+02KM?MlG{v|7bn<3@=KH-IUaga@7r>>T@3hHLo3ED(s zj(^@0SkiCS(!FqRyWW~onCJ{|{^KY#X3-_v6i6deI3h4rYgE7Ad@DEquS1q=v` zJU}6A5l>BGW}-Ci%6(AFWw=Wy)h?VyOeDm26SR5-{WO-{rEry9mRnGw%QDrxN8L`t z%Oe4bE=2+xq|g~Tl!&9*`uDEx6&j-v`9iY{CEV!4wT3juuroj^lAc~xe4ct*17)2^ z#|Xzl=cmQJ9Xxi$YV1tDfzM3%qOTR7NJxCUEv6kE;uF!~tK3QNgeB_7)VSB%2?bkd zCqCdBY_yb;Q%7MH3Jp}Ie9Bi(dZ)<#zcX0>zv@E0;ezxMx_UUXTq5s74{+Af-s1Ub H%=P~O#Amsg literal 0 HcmV?d00001 diff --git a/pages/attacks/XSS_in_Converting_File_Content_to_Text.md b/pages/attacks/XSS_in_Converting_File_Content_to_Text.md new file mode 100644 index 0000000000..74afc04121 --- /dev/null +++ b/pages/attacks/XSS_in_Converting_File_Content_to_Text.md @@ -0,0 +1,26 @@ +--- + +layout: col-sidebar +title: XSS in Converting File Content to Text +author: Mohammad Reza Omrani +contributors: +permalink: /attacks/XSS_in_Converting_File_Content_to_Text +tags: [attack, XSS] + +--- + + {% include writers.html %} + +## Description + +Attackers may be able to execute JavaScript during the conversion of the content +of a file to text, which is commonly known as Cross-Site Scripting (XSS). +If an image containing XSS payload is imported into an image-to-text program, +its output may result in execution of JavaScript code. This vulnerability has been +verified by testing some services that translate text from photos and convert +photos to text. This same process may apply to other vulnerabilities as well! + +## Examples + +Attackers can use programs like Paint to write payloads on blank white photos and send them to targets. +![first example](../assets/images/XSS_in_Converting_File_Content_to_Text.png)