Loading...
Loading...
Setup IBD profile Set up a backend server to serve js file with some HTML tags in string format Example Javascript function PrintPreview(htmlpage) { var page = "<script>function Print(){window.document.getElementById(\"printtool\").setAttribute(\"style\",\"display:none\");window.print();window.document.getElementById(\"printtool\").setAttribute(\"style\",\"\");}; function Close(){close();}</script>"; htmlpage = "<html><head></header><body>" +htmlpage+ scp+ "</body></html>"; myWindow.document.write(htmlpage); } Able to see js tags injected with non html pages with content-type= application/javascript in response
Javascript tag injection is happening for response pages with content-type= application/javascript instead of happening with html pages with content-type = html or xhtml.
Virtual server with the IBD profile and a Javascript file with some HTML tags in string format
None
None
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.