Skip to content

Comment on Don’t use IDs in CSS selectors? (2011)parent

Comments

It seems like you'd need to inject malicious Javascript into the page before you could run an attack like this. General XSS attacks would be the larger, encompassing vulnerability.

It seems malicious HTML could do it, too, if the global element variable replaces some other global object of the same name.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.