Posted in Microsoft promises IE web-standards love
Posted Monday 23rd March 2009 11:19 GMT
Cross site scripting protection?
Earlier versions of IE are much worse than other browsers when it comes to cross site scripting... I haven't tried using 8...
Just some examples, look at the page: http://ha.ckers.org/xss.html which details various encoding methods to bypass XSS filters, many of which work only with IE...
Also if the server returns a content-type of text/plain but the content of the text file looks like html, other browsers will honour the server's content-type and display it as plain text, IE will try to render it as html.
Opinion
David McLeman
My 25 years of comical IT buzzwords
Tim Worstall
Time to take a sniff at the coffee, perhaps
Chris Mellor
Will they have to drag him back like last time?
Popular Stories
Features
Playing the SLA long game
More than just middlemen...
Applications must work for the cloud to float
How a Unix killer crawled from the dot-com bust