Poisonous Style for Dialog Window Bypasses Zone Security
4 Dec. 2002
Summary
By appointing the style of the text in a window (a "ModalDialog" window) a remote attacker is able to execute arbitrary JavaScript and HTML code regardless of zone difference (i.e. he is able to steal the cookies used in any domain).
Credit:
The information has been provided by Liu Die Yu.