[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-Disclosure] internet-explorer: bug or feature?
- To: full-disclosure@xxxxxxxxxxxxxxxx
- Subject: [Full-Disclosure] internet-explorer: bug or feature?
- From: <ko5@xxxxxxxx>
- Date: Wed, 31 Mar 2004 06:30:39 -0800
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
hi!
today i played around a bit with my ie (6.0) to test something and i
found the following behaviour:
when calling a url like
about:mooh
ie shows me a page with the content 'mooh' and when i call
about:<script>alert('*plopp*');</script>
a small alert popps up and says me '*plopp*', so it seems, that i can
inject any code i want.
i am not sure if its what the 'about:'-construct is for, but mozilla
doesn't include everything after the ':' in the body of the document.
sry if this was reportet before, but i haven't found something about
this in google or in the archives.
i think its an interesting behaviour ..
btw: about:mozilla seems to be special .. it looks a bit strange ..
ko5
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.3
wkYEARECAAYFAkBq1kkACgkQn/NqHSmNzSyq1QCfRT3114BilAbYS+PmUIY7Ztke6SQA
oKTK1Raks5IYc1AjMJ8nb1SIYKwV
=9kw/
-----END PGP SIGNATURE-----
Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2
Free, ultra-private instant messaging with Hush Messenger
https://www.hushmail.com/services.php?subloc=messenger&l=434
Promote security and make money with the Hushmail Affiliate Program:
https://www.hushmail.com/about.php?subloc=affiliate&l=427
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html