07 Lab: Reflected XSS into attribute with angle brackets HTML-encoded
Previous06 Lab: DOM XSS in jQuery selector sink using a hashchange eventNext08 Lab: Stored XSS into anchor href attribute with double quotes HTML-encoded
Last updated
Last updated
Verificamos que el input que ingresamos, se refleja en el titulo de la busqueda
Por ende, probamos con estos payloads
"onmouseover="alert(1)