Collected research
HTML+TIME XSS attacks
mario - Pastebin.com
A collected set of Internet Explorer HTML+TIME findings. Attaching behavior:url(#default#time2) through a style attribute exposes timing event handlers such as onbegin on arbitrary elements, and #default#anchorclick with a folder=javascript: attribute brings XSS back through the style attribute on IE8, with links to the MSDN and W3C references.
Record
- Document
- mario - Pastebin.com
- Published by
- Pastebin
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Pastebin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .