3 ms·
This will stop embedding it in <script> but why couldn't the attacking website do the same with eval and substring?
by coconutrandom 15y ago
This will stop embedding it in <script> but why couldn't the attacking website do the same with eval and substring?
- sonnym 15y agoBecause you cannot issue cross-domain AJAX calls, the attacker does not have access to the response body as a string that can be manipulated. https://secure.wikimedia.org/wikipedia/en/wiki/Same_origin_policy https://secure.wikimedia.org/wikipedia/en/wiki/Same_origin_p...
- coconutrandom 15y agoOh duh, I'm dumb.