On Thu, 21 Aug 2008 23:54:44 +0200, Jonas Sicking <[EMAIL PROTECTED]> wrote:

Here is the list of elements that we *don't* execute scripts inside of in firefox:


i.e. <iframe>, <noframes>, <noembed>

Everywhere else we do execute the script.

The reason these elements ended up at the list is in bugs

iframe, noframes and noembed are parsed as CDATA elements


so there can't be any script elements as children of those in text/html. In Opera and WebKit, the script executes in

data:text/xml,<iframe xmlns='http://www.w3.org/1999/xhtml'><script>alert(1)</script></iframe>

and it hasn't caused us any problems AFAIK.

Simon Pieters
Opera Software

Reply via email to