From b191b4a2ef2c965d28fd089b64e0dfb2cce009ef Mon Sep 17 00:00:00 2001 From: Adam Taylor Date: Mon, 10 Aug 2015 19:46:12 -0600 Subject: [PATCH] Added another line to the "Script Injection" section See https://docs.djangoproject.com/en/1.8/ref/utils/#django.utils.html.remove_tags --- blns.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/blns.txt b/blns.txt index 7542be8..8fc6754 100644 --- a/blns.txt +++ b/blns.txt @@ -195,6 +195,7 @@ Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮ " onfocus=alert(document.title) autofocus ' onfocus=alert(document.title) autofocus <script>alert(document.title)</script> +ript>alert('XSS')ript> # SQL Injection #