1
0
mirror of https://github.com/minimaxir/big-list-of-naughty-strings.git synced 2025-09-24 21:01:32 +02:00

Added Full width unicode lt/gt

Browsers will ignore the <script>, but if it's stored into a SQL varchar it get's converted into < and thus a persisted XSS
This commit is contained in:
Adrian D. Alvarez
2015-08-10 20:54:00 -04:00
parent 3fdbc7f944
commit 5fa6653a89

View File

@@ -194,6 +194,7 @@ Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮
onfocus=alert(document.title) autofocus
" onfocus=alert(document.title) autofocus
' onfocus=alert(document.title) autofocus
scriptalert(document.title)/script
# SQL Injection
#