Lab: Reflected XSS into attribute with angle brackets HTML-encoded

preview_player
Показать описание
This lab contains a reflected cross-site scripting vulnerability in the search blog functionality where angle brackets are HTML-encoded. To solve this lab, perform a cross-site scripting attack that injects an attribute and calls the alert function.
Рекомендации по теме
Комментарии
Автор

" onload="alert(1)
" src=1 onerror="alert(1)
" onmouseover="alert(1)

vxqwnduspmjtw
join shbcf.ru