[转]HTML事件属性大全,同时可藏匿危险js代码的事件属性

September 3rd, 2009 no comment

以前被Howard搞的漏洞,需要注意

来自:
http://www.w3schools.com/tags/ref_eventattributes.asp

HTML / XHTML Standard  Event  Attributes

The two attributes below can only be used in <body> or <frameset>:

Attribute Value Description
onload script Script to be run when a document load
onunload script Script to be run when a document unload

Form Events

The attributes below can be used in form elements:

Attribute Value Description
onblur script Script to be run when an element loses focus
onchange script Script to be run when an element change
onfocus script Script to be run when an element gets focus
onreset script Script to be run when a form is reset
onselect script Script to be run when an element is selected
onsubmit script Script to be run when a form is submitted

Image Events

The attribute below can be used with the img element:

Attribute Value Description
onabort script Script to be run when loading of an image is interrupted

Keyboard Events

Valid in all elements except base, bdo, br, frame, frameset, head, html, iframe, meta, param, script, style, and title.

Attribute Value Description
onkeydown script Script to be run when a key is pressed
onkeypress script Script to be run when a key is pressed and released
onkeyup script Script to be run when a key is released

Mouse Events

Valid in all elements except base, bdo, br, frame, frameset, head, html, iframe, meta, param, script, style, and title.

Attribute Value Description
onclick script Script to be run on a mouse click
ondblclick script Script to be run on a mouse double-click
onmousedown script Script to be run when mouse button is pressed
onmousemove script Script to be run when mouse pointer moves
onmouseout script Script to be run when mouse pointer moves out of an element
onmouseover script Script to be run when mouse pointer moves over an element
onmouseup script Script to be run when mouse button is released