webeasy

Easy 5

spbctf

Task: XSS challenge with input inside a deeply nested JavaScript object in a script block. Solution: Break out of the script tag using </script> and inject a new script block, exploiting HTML parser priority over JS parser.

$ ls tags/ techniques/
script_tag_breakouthtml_parser_priority

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]