Re: XSS - URL In Source Of Page
Posted by:
Anonymous User
Date: January 31, 2012 09:15AM
What do you mean it returns the injected code?
Does it return the injected code without sanitization?
Can you provide an example of the output when using one of PaPPy's strings?
Also, keep in mind that the input type is hidden, so you will need to use other methods of XSS if you aren't able to break out of the tag.