Why do browsers prevent cross-site AJAX? -


what of examples of attacks made if possible?

i run website gives away best free pornography in town. people flock it.

as browsing , viewing spectacle of colours , moving imagery, ajax request works it's way through list of domains seeing if logged in of them.

any logged into, send ajax request page on site saves of data has found. way steal private information.

or, can post data forms on pages, along lines of "send me £1000 bank plz k thx".

http://en.wikipedia.org/wiki/same_origin_policy

why cross-domain ajax security concern?


Comments

Popular posts from this blog

linux - Mailx and Gmail nss config dir -

c# - Is it possible to remove an existing registration from Autofac container builder? -

php - Mysql PK and FK char(36) vs int(10) -