You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Nov 15, 2017. It is now read-only.
This is what Chromium itself does. For an extension, I don't see how this is possible, as extensions can't block inline scripting (issue #35). I suppose the best option is to have webkit fix the code so this bypass doesn't work. I am trying to find out if there is a bug opened for this one particular case.
As in http://labs.lachisterablanca.com/poc/bypass/index.php?%3Cscript%3Ealert(%27XSS%20WITH%20WHITESPACES%27);%3C/script%3E=anyValue
The text was updated successfully, but these errors were encountered: