Web Hack List

Other nomination

HTML+TIME XSS attacks

A collected set of Internet Explorer HTML+TIME findings. Attaching behavior:url(#default#time2) through a style attribute exposes timing event handlers such as onbegin on arbitrary elements, and #default#anchorclick with a folder=javascript: attribute brings XSS back through the style attribute on IE8, with links to the MSDN and W3C references.

Record

Published by
Pastebin

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Pastebin, first published at the original source. Preserved copies are kept so the citation survives its host.