Web Hack List

Collected research

Postcards from the post-XSS world

Examines risks that remain when injected HTML cannot execute scripts, including markup-based data leaks, CSS behavior, and interference with application logic. Explains why script restrictions alone do not make HTML injection safe, and distinguishes browser defenses from complete input handling.

Record

Researcher
Michal Zalewski
Published by
Michal Zalewski
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Michal Zalewski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .