W3C CSS :visited Pseudo-Class...

- AV AC AU C I A
发布: 2002-02-14
修订: 2025-04-13

Cascading Style Sheets (CSS) are a series of specifications produced and published by the World Wide Web Consortium (W3C). They are intended to provide a standard for adding literal formatting and layout information to HTML documents. CSS-1 is partially implemented by most browsers, including Netscape and Internet Explorer. Features defined in the CSS specification include the ':visited' pseudo class, which is used to define styles used on links to previously visited pages and to include external references in style declarations. Used together, these features may lead to an information-disclosure vulnerability. An attacker must construct a malicious web pageand include a link to a known third-party page. The attacker may then define a ':visited' style for this link and include a reference to an attacker-controlled file within the style declaration. When the malicious page is loaded, the user's browser will access the external reference only if it is required. The attacker may then...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息