Linked by Thom Holwerda on Fri 20th Mar 2009 13:51 UTC, submitted by google_ninja
Thread beginning with comment 354168
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[2]: The problem isn't any particular browser
by rajj on Fri 20th Mar 2009 18:37
in reply to "RE: The problem isn't any particular browser"
I should have said arbitrary input, but I don't think you can say that javascript is strictly restricted to DOM manipulation either.
The point stands; the end result of all of this is endless turd polishing. We start with a turd; we end with a smoother turd, but it's still a turd nevertheless.




Member since:
2006-02-05
Javascript is used as a dom scripting language though, so its not arbitrary code. To get arbitrary code to run, it is embed and object tags, plus some kind of browser bug to get it to execute the plugin outside of any sort of sandbox.