Greasy Fork

Greasy Fork is available in English.

@-posting

Link to posts in the same 4chan thread with "@".

< 脚本 @-posting 的反馈

提问 / 留言

§
发布于:2017-03-17

Script injection vulnerability

The script as is takes the text value of a node and assigns it to the HTML of its replacement. So if the text contains something like <img onerror=alert(0) src=x> that gets converted to HTML.

发布留言

登录以发布留言。