From f594d6aa2a833f43d23d3870e4e5d8c690586ed2 Mon Sep 17 00:00:00 2001 From: Joseph Lennox Date: Mon, 10 Aug 2015 14:16:11 -0700 Subject: [PATCH 1/3] Negative number validation errors. --- blns.txt | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blns.txt b/blns.txt index b13a9c8..902a4ca 100644 --- a/blns.txt +++ b/blns.txt @@ -33,6 +33,8 @@ $1.00 0,,0 , 0,0,0 +--1 +- 999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999 NaN Infinity From 02e7317f732adeb416ffa2dcb7a803b277a5879e Mon Sep 17 00:00:00 2001 From: Joseph Lennox Date: Mon, 10 Aug 2015 14:29:33 -0700 Subject: [PATCH 2/3] Negative number validation errors. --- blns.txt | 2 ++ 1 file changed, 2 insertions(+) diff --git a/blns.txt b/blns.txt index 902a4ca..705b7ed 100644 --- a/blns.txt +++ b/blns.txt @@ -35,6 +35,8 @@ $1.00 0,0,0 --1 - +-. +-, 999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999 NaN Infinity From 9dbe44bf69ca91c52c8ad001aca3b2b6a7b14181 Mon Sep 17 00:00:00 2001 From: Joseph Lennox Date: Mon, 10 Aug 2015 14:30:34 -0700 Subject: [PATCH 3/3] XSS attribute escapes without lt/gt/quote symbols. --- blns.txt | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/blns.txt b/blns.txt index 705b7ed..e1910eb 100644 --- a/blns.txt +++ b/blns.txt @@ -186,8 +186,13 @@ Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮ "> -> '> +> + +< / script >< script >alert(document.title)< / script > + onfocus=alert(document.title) autofocus +" onfocus=alert(document.title) autofocus +' onfocus=alert(document.title) autofocus # SQL Injection #