Re: XSS mitigation in browsers

On 1/20/11 7:10 PM, sird@rckc.at wrote:
> Here's the PoC:
> http://eaea.sirdarckcat.net/epicwin.xhtml
>
> Though, only works on xhtml :(

The fact that it works at all is a bug.

-Boris

Received on Friday, 21 January 2011 04:02:27 UTC