Dom Clobbering
基础知识
<form id=x></form>
<script> console.log(typeof document.x) //[object HTMLFormElement] </script><a href="controlled string" id=x></a>
<script>
console.log(x);//controlled string
</script>数组和属性
<a id=x>
<a id=x name=y href=controlled>
<script>
console.log(x[1])//controlled
console.log(x.y)//controlled
</script>绕过过滤器
Clobbering window.someObject
window.someObject覆盖文档对象
在元素被篡改后写入
Clobbering Forms
参考资料
最后更新于