Mi chiedevo se le richieste GET riportate di seguito da un file HTML e da un file javascript sono vulnerabili a AJAX Hijacking / JavaScript Hijacking?
AJAX Hijacking: link JavaScript Hijacking: link
1)
var req = new XMLHttpRequest();
req.open("GET", queryUrl, false);
req.setRequestHeader("Accept", "application/json");
req.setRequestHeader("Content-Type", "application/json; charset=utf-8");
req.onreadystatechange = function () {
if (this.readyState == 4) {
if (this.status == 200) {
//do something }
}
}
req.send();
2)
var req = new XMLHttpRequest();
req.open("GET", encodeURI(ODataPath() + type + "Var1"+ Value1+"), true);
req.setRequestHeader("Accept", "application/json");
req.setRequestHeader("Content-Type", "application/json; charset=utf-8");
req.onreadystatechange = function () {
if (this.readyState == 4 /* complete */) {
req.onreadystatechange = null;
// Do Something
};
req.send();
};