topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday December 13, 2024, 5:02 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: European security group issues warning on HTML5  (Read 2297 times)

app103

  • That scary taskbar girl
  • Global Moderator
  • Joined in 2006
  • *****
  • Posts: 5,885
    • View Profile
    • Donate to Member
European security group issues warning on HTML5
« on: August 06, 2011, 02:42 AM »
ENISA look at 13 specifications within HTML5 and found 51 security issues. Some of the issues can be fixed by tweaking the specifications, while others are more risks based on the features that users should be alerted to, Hogben said. One of the features that concerns ENISA in the paper is termed "form tampering."

The HTML5 specification allows for the "submit" button for a Web-based form to be placed anywhere on a Web page. It means it would be possible for an attacker to inject other HTML onto the page, such as a different form button, and then cause the information in the form to be sent to the attacker rather than the legitimate website.