Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: XSS - Double Quote break out and White Space filtered May 28 2009 09:00AM
PortSwigger (mail portswigger net)
Have you checked whether backticks are allowed? IE interprets backticks in
the same way as quotes. So you may be able to use something like:

``onclick=alert(1)

-----Original Message-----
From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]] On
Behalf Of arvind doraiswamy
Sent: ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus