开发者

link shenanigans?

开发者 https://www.devze.com 2023-02-23 04:15 出处:网络
If using an HTML whitelist and HTMLPurifier, are there any shenanigans a malicious user can execute if <a></a> is allo开发者_JAVA百科wed?

If using an HTML whitelist and HTMLPurifier, are there any shenanigans a malicious user can execute if <a></a> is allo开发者_JAVA百科wed?

For atmosphere:

link shenanigans?


Not if you only allow the href attribute and don't allow the javascript: pseudo protocol.

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号