Weaponizing Search Engines: Efficient Discovery and Exploitation of XSS in Public-Facing Endpoints
At a glance
- Citations
- 1
- References
- 31
- Comments
- 0
Abstract
In this research, a prevalent Cross-Site Scripting (XSS) vulnerability in listserv systems is examined, and its surprisingly simple discovery using fundamental Google dorking techniques is demonstrated. The analysis identifies a sizable number of servers that are susceptible, especially those in governmental and educational organizations, and that frequently do not have publicly available vulnerability disclosure policies. A large attack surface was made evident without the need of specialist security tools by using an effective, self-developed Google dork, demonstrating how easy it is to find these kinds of vulnerabilities. The study also describes how the attack may be carried out with no technical knowledge using easily accessible payloads from sources such as the Google Hacking Database. The results highlight how urgently these crucial industries need to adopt better security procedures and transparent vulnerability disclosure systems.
Publication details
- DOI
- 10.1109/aiiot65859.2025.11105357
- OpenAlex
- W4413180231
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.