Collected research
Postcards from the post-XSS world
Examines risks that remain when injected HTML cannot execute scripts, including markup-based data leaks, CSS behavior, and interference with application logic. Explains why script restrictions alone do not make HTML injection safe, and distinguishes browser defenses from complete input handling.
Record
- Researcher
- Michal Zalewski
- Published by
- Michal Zalewski
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Michal Zalewski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .