3

XSS attempt

Submitted by nitori in test

![" onload="console.log('Im in your mainframe :3')"](/apple-touch-icon-precomposed.png)

turns into

" onload="console.log('Im in your mainframe :3')"

Comments

You must log in or register to comment.

2

nitori wrote (edited )

ebic fail

again, good HTML sanitizing

1

nitori wrote

Hmm let's try adding a span into a link

[<span onload="console.log('Im in your mainframe :3')"></span>](/)

turns into

<span onload="console.log('Im in your mainframe :3')"></span>