4 ms·
It just change `windown.location`. And it would be very limited if JS can't change `window.location` to outside its current domain.
by joesb 8y ago
It just change `windown.location`.
And it would be very limited if JS can't change `window.location` to outside its current domain.
- baddox 8y agoThis exploit uses the history API, which allows JavaScript to change the URL in the browser URL bar to another URL with the same origin without actually causing a new full page request. The same-origin policy has always been in place, because it would obviously be a huge vulnerability to allow any web page to pretend to be a different website. Changing window.location is different: it allows you to change the browser URL bar to any URL (including google.com, etc.), but it actually causes the browser to do a normal page load of the new URL, just like if the user had clicked a link to the new URL. Thus there is no spoofing vulnerability exposed by the window.location feature.