Skip to content

Instantly share code, notes, and snippets.

@KageShiron
Created April 24, 2023 14:45
Show Gist options
  • Save KageShiron/e863b5b6ca02e295fac8c98f344545eb to your computer and use it in GitHub Desktop.
Save KageShiron/e863b5b6ca02e295fac8c98f344545eb to your computer and use it in GitHub Desktop.
<h2>target="_blank"なし</h2>
<a href="javascript:alert(document.domain)">なし(javascript:)</a>
<a href="data:text/html,<script>alert(document.domain)</script>">>なし(data:)</a>
<br/>
<h2>target="_blank"あり</h2>
<a href="javascript:alert(document.domain)" target="_blank">あり(javascript:)</a>
<a href="data:text/html,<script>alert(document.domain)</script>" target="_blank">あり(data:)</a>
<h2>target="test"</h2>
<a href="javascript:alert(document.domain)" target="test">あり(javascript:)</a>
<a href="data:text/html,<script>alert(document.domain)</script>" target="test">あり(data:)</a>
<h2>target="ifr"</h2>
<a href="javascript:alert(document.domain)" target="ifr">あり(javascript:)</a>
<a href="data:text/html,<script>alert(document.domain)</script>" target="ifr">あり(data:)</a>
<iframe src="/test.php" name="ifr"></iframe>
<h2>target="ifr2"</h2>
<a href="javascript:alert(document.domain)" target="ifr2">あり(javascript:)</a>
<a href="data:text/html,<script>alert(document.domain)</script>" target="ifr2">あり(data:)</a>
<iframe src="https://example.com" name="ifr2"></iframe>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment