- From: <bugzilla@jessica.w3.org>
- Date: Wed, 28 Apr 2010 16:51:25 +0000
- To: public-html-bugzilla@w3.org
http://www.w3.org/Bugs/Public/show_bug.cgi?id=9602 --- Comment #4 from Skyphire <sasha@scarletred.nl> 2010-04-28 16:52:04 --- Lachlan, maybe it's a good idea to read the description once more. My PoC doesn't use JavaScript at all. Yours does. World of difference here, because many people block JavaScript as a security measure. Due to iframe overlapping (try only iframe overlapping in Firefox to see what happens) the iframe beneath the original trusted one gets focused, you will notice if you reconstruct it carefully, that there will be no apparent difference, because the focus appears to be set in first iframe, but it actually gets set to the 2nd iframe beneath, tricking a unsuspecting user to enter a password or other sensitive data for example. Forgot to add that a SPACE can trigger the SUBMIT button if it received focus. -Skyphire -- Configure bugmail: http://www.w3.org/Bugs/Public/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are the QA contact for the bug.
Received on Wednesday, 28 April 2010 16:52:06 UTC