我只允许用户带上你管或任何其他视频来源,要求他们提交他们所接收的密码的<代码>src。 然后,我将其节省到数据库中,并通过一机装上。 然而,如果有一个来源,例如src=”http://innocent.com/hackingContent.php>
,那么我的网站是否容易发生Xs攻击?
I am estimating that the user may have a malicious script in that src
which will load as soon as the iframe embeds the source into my own html.
EDIT What if the src contains <script type="text/javascript" src="evilScript.js"></script>
. Although I am using a preg_match
just to make sure that its a url only.