Other nomination
HTML+TIME XSS attacks
A collected set of Internet Explorer HTML+TIME findings. Attaching behavior:url(#default#time2) through a style attribute exposes timing event handlers such as onbegin on arbitrary elements, and #default#anchorclick with a folder=javascript: attribute brings XSS back through the style attribute on IE8, with links to the MSDN and W3C references.
Record
- Published by
- Pastebin
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Pastebin, first published at the original source. Preserved copies are kept so the citation survives its host.