Or there are other ways to evaluate the code
eval() script -parsing, JavaScript Turing-complete, . . . svinto . window.eval, , , ( ):
- new ('code')()
- document.write( '% 3Cscript > % 3C/ script > ')
- document.createElement( 'script'). AppendChild (document.createTextNode( ''))
- window.setTimeout('code', 0);
- window.open(...). Eval ( '')
- location.href="JavaScript:
- IE, / node.setExpression('someproperty', 'code')
- , node.onomeevent = 'code';
- , Object.prototype.eval('code')
javascript?
createElement ('iframe'). src= 'http://evil.iframeexploitz.ru/aff=2345' - , ... , script , , . " !" , . .
, -?
:
- , , GreaseMonkey
- vet script
- ( JavaScript) -,
, , Google Caja. , ; , - , , .