Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: XSS - Double Quote break out and White Space filtered May 29 2009 02:48AM
Jeff Williams (planetlevel gmail com)
In problem 1, since there are no quotes, there are lots of characters that
will terminate an attribute, like %00, %08, CR, LF, VT, space, tab, etc...

I think you're out of luck on problem 2. You *can* break out of a quoted
string inside javascript without the corresponding quote by "injecting up"
a...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus