XSS attacks and style attributes

后端 未结 4 1363
借酒劲吻你
借酒劲吻你 2020-12-03 00:53

There are known Style Attribute XSS attacks like:

Or

4条回答
  •  囚心锁ツ
    2020-12-03 01:44

    This does not work due to click-jacking vulnerability.

    Example:

      
    

    Found at: http://www.bioinformatics.org/phplabware/forum/viewtopic.php?id=164

    The code would be perfectly validated but it may cause serious damage.

    So - rule of thumb use very strict white list or do not allow style attributes.

提交回复
热议问题