webeasy

Easy 0

spbctf

Task: User input placed in HTML input value attribute without sanitization. Solution: Attribute breakout XSS using double quote to close attribute, then inject img tag with onerror handler.

$ ls tags/ techniques/
attribute_breakout_xssimg_onerror_xss

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]