in reply to CGI::Ajax. Getting content of second.html file to resultant div of one.pl (same/cross domain)
If you incorporate someone else's page inside of your own verbatim, then, if said page has <script> elements on it, then whoever owns that page gains the ability to run arbitrary scripts in your own domain's browser context — remember that the owners of the website serving that page can change the contents of that page any time they want — meaning they can call your javascript functions with whatever arguments they want, read your cookies, and thus masquerade as and do anything that your own javascript can do. Which then means you either have to
This is all before we get into how you're incorporating the page.
What is it you're actually trying to do?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: CGI::Ajax. Getting content of second.html file to resultant div of one.pl (same/cross domain)
by msinfo (Sexton) on Jun 07, 2013 at 02:44 UTC | |
|
Re^2: CGI::Ajax. Getting content of second.html file to resultant div of one.pl (same/cross domain)
by Anonymous Monk on Jun 06, 2013 at 23:33 UTC | |
by wrog (Friar) on Jun 08, 2013 at 05:33 UTC | |
by Anonymous Monk on Jun 08, 2013 at 09:46 UTC | |
by wrog (Friar) on Jun 09, 2013 at 07:43 UTC |