|
 |
Articles |
|
|
|
 |
GEEK |
|
|
|
 |
User's box |
|
|
|
 |
Shoutbox |
| Domuk No, not an
issue with
the PHP - I
was
responding
to "AJAX not
being cross
site is
annoying" |
| MaxMouse Really? i
thought that
would only
be important
if the user
had some
kind of
control over
where the
XML came
from, if you
hard code it
(As in a PHP
file)
wouldn't
that
eliminate
XSS attacks? |
| Domuk Yes, but
very, very
necessary.
AJAX
requests run
in the
context of
the browser,
there'd be
no security
if it was
cross-domain
. |
| MaxMouse AJAX not
being cross
site is
annoying,
all other
scripts can
be used in
that way,
having to
resort to
PHP to patch
it is a
shame. |
| SAJChurchey thx MaxMouse |
|
|
 |
Donate |
|
Donate and help us fund new challenges
|
|
|
|
Due Date:
|
Nov 30 |
|
November Goal:
|
$40.00
|
|
Gross:
|
$0.00 |
|
Net Balance:
|
$0.00 |
|
Left to go:
|
$40.00 |
|
|
|
 |
News Feeds |
|
|
|
|
|
|
CoDebug |
Posted by KingCepheus Tue 20th Oct 06:10 (modification of posting from CodeX )001 002 003 004
|
Pate this into your URL bar and smash enter, you know you want to...
javascript: alert("CodeX says:\n\"Hello "+document.cookie.match(/username=(.+?); /)[1]+"!\"\n:3");
|
Submit a correction or amendment below. (click here to make a fresh posting) |
|
|
|
|
 |
Recent Pastes |
|
| | |