New Attack Combines Self-XSS and Clickjacking

A researcher has demonstrated an attack that combines Clickjacking and a type of Cross Site Scripting (XSS) called Self-XSS. The new attack can trigger Self-XSS on pages that are also vulnerable to Clickjacking, the researcher says.

read more

Article Link: http://feedproxy.google.com/~r/Securityweek/~3/JSD2zIXnbt4/new-attack-combines-self-xss-and-clickjacking