Brief description:
DOM-based cross-site, malicious users may inject Vulnerable applications to fool users to collect data from their JavaScript, VBScript ActiveX, HTML, or Flash. Attackers can steal session cookies and take over accounts to simulate users. It can also be modified to present the content to the user's page.
Detailed description:
The script code executed by using the document. write () or document. writeln () function is part of the path from document. location.
Code executed: http://img.gd.sohu.com/js/pv.js
For more information about DOM-based cross-site deployment, see
Hacker attack and defense technology book: Web practice article: http://www.bkjia.com/Article/201110/108891.html
The script code executed by using the document. write () or document. writeln () function is part of the path from document. location.
Code executed: http://img.gd.sohu.com/js/pv.js
Solution:
Filter ..
Copyright Disclaimer: Reprinted with the source zeracker @ wooyun