General Actions:
Dixit Wikipedia : "WebKit is a layout engine designed to allow web browsers to render web pages. WebKit powers Google Chrome and Apple Safari that by December 2011 held 33.35% of the browser market share between them (according to StatCounter). It is also used as the basis for the experimental browser included with the Amazon Kindle ebook reader, as well as the default browser in the iOS, Android and webOS mobile operating systems."
Webkit is used as the rendering engine of numerous browsers :
It is also used in others softwares rendering HTML :
Webkit uses libxslt as its XSLT engine. Old versions were not restricting write access by the engine to the file system, leading to a remotely exploitable vulnerability (CVE-2011-1774). This was patched in Changeset 79159 by adding appropriate calls to xsltSetSecurityPrefs().
PoC included on the libxslt page demonstrate the vulnerability :


Two modules are included in Metasploit :
An exploit for HP webOS 3.x was developed. This exploit drops a backdoor which is later executed with root privileges at boot time. The exploit is composed of two files :
Browsing the XML file from a vulnerable device is enough to trigger the exploit. This was patched during the 3.0.2 OTA update.
Welcome on the XSLT Hacking Encyclopedia !
You may be interested by the Engines and Applications pages.
Link to the blog
Twitter: @Agarri_FR
The "tagcloud" macro is not in the list of registered macros. Verify the spelling or contact your administrator.