We have some code that removes "dangerous" attributes and tags from HTML.  I noticed that style is among the list of "dangerous" attributes.  What could be the risk from that attribute?
In IE you can include @behaviors in there which can load little Javascripts.
With CSS3 you can also interject little bits of text, which could be dangerous depending on your website.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With