webeasy

Easy 1

spbctf

Task: User input placed inside JavaScript string in console.log() without escaping. Solution: JS string breakout XSS using double quote to close string, inject prompt(), and comment out remainder.

$ ls tags/ techniques/
js_string_breakout_xssscript_context_xss

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]