#26 MIME-sniffing

Closed
opened 5 years ago by sindre · 0 comments
sindre commented 5 years ago

MIME sniffing can be used for XSS. It is standard to turn off MIME in the X-Content header.

MIME sniffing can be used for XSS. It is standard to turn off MIME in the X-Content header.
sindre added this to the Required fixes milestone 5 years ago
sindre added the
webpy
label 5 years ago
sindre added the
bug
label 5 years ago
sindre added the
security misconfiguration
label 5 years ago
sindre referenced this issue from a commit 5 years ago
sindre modified the milestone from Required fixes to Optional vulnerabilities 5 years ago
Sign in to join this conversation.
Loading…
Cancel
Save
There is no content yet.