JavaScriptµÄ Cross Site ½Å±¾×¢Èë·çÏÕ
½ñÌìÓÐÈËÀ´¹«Ë¾ÍÆÏúÍøÕ¾°²È«É¨ÃèÈí¼þ£¬ÑÝʾÁ˶ÔJSµÄ¿çÓò½Å±¾×¢Èë·çÏÕµÄɨÃ裬ÒÔǰûÒâʶµ½£¬½ñÌìÓÐËùÁ˽⡣Èç¹ûÄúµÄ³ÌÐòÒ³ÃæÓÐÒÔÏÂÇé¿ö£¬ÄÇôJS½Å±¾×¢ÈëµÄ·çÏվͺܴó£º
1£©Ò³Ãæ´ò¿ªÊ±£¬URL ÓÐij¸ö²ÎÊý£¬ÀýÈç XXPage.aspx?XXParam=XXValue
2£©aspxÒ³ÃæÀïÓÐÈçÏ´úÂ룺
<script>
var p = "<%=Request["XXParam"];%>";
</script>
×¢Èë·çÏÕÈçÏ£º
1£©ºÚ¿Í¼ÙÃ°ÍøÕ¾Éí·Ý·¢ËÍÓʼþ¸øÓû§£¬Óû§´ò¿ªÍøÒ³Á´½Ó£¬Á´½ÓËäÈ»ÊÇÖ¸Ïò XXPage.aspx£¬µ« XXParam È´±»×öÁ˸ÄÔ죬ÀýÈ磺XXParam ±»ÉèÖÃΪ "; document.location.href = 'http://www.xxx.com/XXFakePage.aspx';//"¡£×¢Òâ£¬Ç°ÃæµÄË«ÒýºÅÊÇÓÃÀ´ÆÁ±Î var p = " µÄ£¬ºóÃæ½ô½ÓמÍÊÇÒ»¸öJSÒ³ÃæÌø×ªÓï¾ä£»×îºóÃæµÄ //" ÊÇÓÃÀ´ÆÁ±Î JS ½Å±¾ÖеĺóÒýºÅµÄ¡£
Äã²Â½á¹û»áÔõôÑù£¿Ò³ÃæÖ±½Ó±»Ìø×ªµ½ http://www.xxx.com/XXFakePage.aspx£¬Èç¹ûÕâ¸öÒ³ÃæÊǼÙÃ°Ò³Ãæ£¬²¢ÇÒÕâ¸öÒ³ÃæÊÇǶÈëÔÚ Frameset ÀïµÄ£¬ÄÇÓû§»áÔÚºÁÎÞ¾õ²ìµÄÇé¿öÏ£¬°Ñ×¢ÈëÓû§Ãû¡¢ÃÜÂë¡¢ÒøÐп¨Õ˺ÅÃÜÂëÌá½»µ½¼ÙÃ°Ò³ÃæÉÏ£¡£¡
¶Ô²ß£º
·½·¨Ò»£º²»ÒªÓà <%=Request["XXParam"];%> À´½âÎö²ÎÊýÖµ£¬¶øÖ±½ÓÓà JS ½Å±¾´ÓURL»ñÈ¡²ÎÊýÖµ
·½·¨¶þ£º°Ñ²ÎÊýÖµÏÈ·ÅÔÚ HIDDEN ¿Ø¼þÀÀýÈç: <input type=hidden id=xxhid value="<%=Server.HtmlEncode(Request["XXParam"]);%>"> ÀȻºóÔÚ JS Àï¸ÄΪ var p = document.all.xxhid.value;
Ó¦¸Ã»¹ÓÐÆäËû·½·¨£¬ÒÔÉÏ·½·¨Ö»ÊÇʾÒ⣬ûÓÐÈ¥±àÒ룬½ö¹©²Î¿¼¡£
Ïà¹ØÎĵµ£º
Ò»¡¢ÐÂÔöÒ»¸öoption
var sel=document.getElementById("selectµÄid");
var op=document.createElement("option");
op.value=Öµ;
op.text=ÏÔʾÎı¾;
sel.add(op);
¶þ¡¢É¾³ýÒ»¸öoption
var sel=document.getElementById("typelist");
if(sel.selectedIndex==-1)
alert("ÇëÑ¡ ......
JavaScript ÊǸù¾Ý "ECMAScript"±ê×¼ÖÆ¶¨µÄÍøÒ³½Å±¾ÓïÑÔ¡£Õâ¸ö±ê×¼ÓÉ ECMA ×éÖ¯·¢Õ¹ºÍά»¤¡£ECMA-262
ÊÇÕýʽµÄ JavaScript ±ê×¼¡£Õâ¸ö±ê×¼»ùÓÚ JavaScript (Netscape) ºÍ JScript
(Microsoft)¡£Netscape (Navigator 2.0) µÄ Brendan Eich ·¢Ã÷ÁËÕâÃÅÓïÑÔ£¬´Ó 1996
Ä꿪ʼ£¬ÒѾ³öÏÖÔÚËùÓÐµÄ Netscape ºÍ Micro ......
Ëæ×Åä¯ÀÀÆ÷°²È«ÐÔµÄÌá¸ß£¬ÒªÊµÏÖͼƬԤÀÀÒ²Ô½À´Ô½À§ÄÑ¡£
²»¹ýȺÖÚµÄÖÇ»ÛÊÇÎÞÏ޵ģ¬ÍøÉÏÒ²Óкܶà±äͨ»òÏȽøµÄ·½·¨À´ÊµÏÖ¡£
ÔÚÑо¿Á˸÷ÖÖÔ¤ÀÀ·½·¨ºó£¬×÷Ϊ×ܽᣬдÁËÕâ¸ö³ÌÐò£¬¸ú´ó¼ÒÒ»Æð·ÖÏí¡£
ÉÏ´ÎдµÄ¼ò±ãÎÞË¢ÐÂÎļþÉÏ´«ÏµÍ³×î³õµÄÄ¿µÄ¾ÍÊÇÓÃÀ´ÊµÏÖÕâ¸öͼƬԤÀÀЧ¹û¡£
¼æÈÝ£ºie6/7/8, firefox 3.5.5
ºǫ֧́³ÖÏ»¹¼æÈÝ ......
<script language="javascript">
function test()
{
var rng=document.body.createTextRange();
alert(rng.text)
}
function test1()
{
var rng=document.body.createTextRange();
alert(rng.htmlText)
}
</script>
<input type="button" onclick="test()"& ......
×ªÔØ:JavaScript»ñÈ¡Ò³Ãæ¿í¶È¸ß¶È´óÈ«
µØÖ·:http://www.cnblogs.com/wcg249165510/archive/2009/02/20/1394749.html
ÍøÒ³¿É¼ûÇøÓò¿í£ºdocument.body.clientWidth
ÍøÒ³¿É¼ûÇøÓò¸ß£ºdocument.body.clientHeight
ÍøÒ³¿É¼ûÇøÓò¿í£ºdocument.body.offsetWidth(°üÀ¨±ßÏߵĿí)
ÍøÒ³¿É¼ûÇøÓò¸ß£ºdocument.body.offsetHeight(° ......