ENISA look at 13 specifications within HTML5 and found 51 security issues. Some of the issues can be fixed by tweaking the specifications, while others are more risks based on the features that users should be alerted to, Hogben said. One of the features that concerns ENISA in the paper is termed "form tampering."The HTML5 specification allows for the "submit" button for a Web-based form to be placed anywhere on a Web page. It means it would be possible for an attacker to inject other HTML onto the page, such as a different form button, and then cause the information in the form to be sent to the attacker rather than the legitimate website.
Page created in 0.022 seconds with 22 queries.