[Webkit-unassigned] [Bug 14692] Cross frame scripting allowed by Webkit in layout test

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon Aug 6 21:32:31 PDT 2007


http://bugs.webkit.org/show_bug.cgi?id=14692





------- Comment #2 from just1gb at gmail.com  2007-08-06 21:32 PDT -------
Created an attachment (id=15854)
 --> (http://bugs.webkit.org/attachment.cgi?id=15854&action=view)
XSS Cookie demo

Please find an example of HTML to read cookie of google.com. This HTML can be
on any domain.


-- 
Configure bugmail: http://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list