Paid Advertising
web application security lab

Meta using link

Okay, so today I decided to pick on Opera. I found two holes, that are basically the same that use a Meta tag to import a remote style sheet by setting the link tag header. Pretty tricky. Using the same method I can call JavaScript directly, although I don’t like that one as much because it has the word JavaScript on the page.

Respond here or Discuss On the Forums