Hotmail\'s filter identifies \"expression()\" syntax in a CSS attribute. According to Hasegawa Yosuke\'s post(http://archive.openmya.devnull.jp/2006.08/msg00369.html), in some character encodings(e.g. GB2312), we can substitute some special double-byte chars for the corresponding chars in \"expression()\". In this case, we can create a malformed CSS attribute, which Hotmail\'s filter fails to inspect and filter the \"expression()\" syntax.
Hotmail and Windows Live Mail
Microsoft was notified on Sep 25th, 2006.
The bug is now fixed.
暂无评论