Netscape Navigator 'about:' Domain...

- AV AC AU C I A
发布: 2001-04-09
修订: 2025-04-13

Due to a flaw in Navigator's security code, all URLs in the about: protocol are considered to be part of the same domain. If arbitrary Javascript code is placed in a GIF's comment field, it is treated like a normal HTML page. The Javascript code will run from the image information page in the internal about: 'domain'. This issue has also been reported in commented JPEG files.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息