We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
<object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTs8L3NjcmlwdD4="> 直接在浏览器弹了,应该也算对吧
<object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTs8L3NjcmlwdD4=">
The text was updated successfully, but these errors were encountered:
不能算合格,新开的 context,与原页面是独立的上下文,受同源限制,危害小很多。
拦截脚本没能捕获到这个 alert,原因见源码 https://github.com/haozi/xss-demo/blob/master/src/data/sandbox.raw#L10
Sorry, something went wrong.
No branches or pull requests
<object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTs8L3NjcmlwdD4=">
直接在浏览器弹了,应该也算对吧
The text was updated successfully, but these errors were encountered: