But binding a value that an attacker might control into innerHTML normally causes an XSS ... which causes Angular to let binding into <iframe src> :.
確定! 回上一頁