src attribute on iframe tags

src attribute of iframe tag will initiate a get request, this is not checked xhr see inside, looking directly at all, if you see there are post xhr request, not the iframe src can send a post request, but the request src come back the page, which has initiated form post request forms, etc.

Guess you like

Origin www.cnblogs.com/antyhouse/p/12169280.html