tomnomnom / hacks

A collection of hacks and one-off scripts
2.12k stars 633 forks source link

add <h1> #33

Open cyb3rsalih opened 3 years ago

cyb3rsalih commented 3 years ago

When I was start to BB, I did the what kxss do, manually. One day saw a case that, <>'" characters are encoding, but the tags didn't. So I could inject <svg onload=alert(1) easily. I really don't know why but I think adding a basic tag (like \<h1>) will cover this case also.

Have a nice day!