AntiPattern
External Resource Injection
external-resource-and-href-injection
Client-side and server-side code changes allow untrusted external inputs (e.g., manipulated browser location, injected anchors/HTML into href, or cross-domain SWF access) to be followed or executed, so attacks succeed via pseudo-protocol calls or resource loading where intent assumed isolation.