2 |
<html> |
<html> |
3 |
<head> |
<head> |
4 |
<title>cssText = '' and die</title> |
<title>cssText = '' and die</title> |
5 |
|
<style></style> |
6 |
</head> |
</head> |
7 |
<body> |
<body> |
8 |
<p><textarea></textarea></p> |
<p><textarea></textarea></p> |
9 |
<p><button type="button" onclick=" |
<p><button type="button" onclick=" |
10 |
document.getElementsByTagName ('iframe')[0].contentWindow.document.getElementsByTagName ('style')[0].styleSheet.cssText = document.getElementsByTagName ('textarea')[0].accessKey + ''; |
document.getElementsByTagName ('style')[0].styleSheet.cssText = document.getElementsByTagName ('textarea')[0].accessKey + ''; |
11 |
">Click this button is safe</button></p> |
">Clicking this button is safe</button></p> |
|
<p><iframe src="javascript:'<style></style>'"></iframe></p> |
|
12 |
</body> |
</body> |
13 |
</html> |
</html> |