thespanner.co.uk thespanner.co.uk

thespanner.co.uk

The Spanner

Javascript blog with messed up syntax inside. New IE mutation vector. Wednesday, 17 June 2015. I was messing around with a filter that didn’t correctly filter attribute names and allowed a blank one which enabled me to bypass it. I thought maybe IE had similar issues when rewriting innerHTML. Yes it does of course. The filter bypass worked like this:. Img = script alert(1) /script. Div='/x="'>