<script> | |
document.testExpando = "It's me too!"; | |
parent.childEval = eval; | |
parent.childEvalCaller = (function() | |
{ | |
// Capture window.window into a variable, since this property always returns null once | |
// the context is navigated. | |
var w = window; | |
return function(s) { | |
return w.eval(s); | |
} | |
})(); | |
parent.childLocalEvalCaller = (function() | |
{ | |
var e = eval; | |
return function(s) { return e(s); }; | |
})(); | |
location.href = "http://localhost:8000/security/resources/xss-eval3.html"; | |
</script> |