Update sectraining.md
This commit is contained in:
parent
5c9876ad8a
commit
addf4f6a94
1 changed files with 7 additions and 7 deletions
|
|
@ -22,10 +22,10 @@ JavaScript frameworks (e.g., Angular, React) or server-side templating systems (
|
||||||
|
|
||||||
|context|vulnerable code | java |
|
|context|vulnerable code | java |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
|HTML Body |<div>USER-CONTROLLED-DATA</div> | `Encode.forHtml` |
|
|HTML Body |<div>USER-CONTROLLED-DATA</div> | `Encode.forHtml` |
|
||||||
|HTML Attribute| <input type="text" value="USER-CONTROLLED-DATA"> |`Encode.forHtmlAttribute`|
|
|HTML Attribute| <input type="text" value="USER-CONTROLLED-DATA"> |`Encode.forHtmlAttribute`|
|
||||||
|URL Parameter| <a href="/search?value=USER-CONTROLLED-DATA">Search</a> |`Encode.forUriComponent`|
|
|URL Parameter| <a href="/search?value=USER-CONTROLLED-DATA">Search</a> |`Encode.forUriComponent`|
|
||||||
|CSS String |<div style="width: USER-CONTROLLED-DATA;">Selection</div>| `Encode.forCssString`|
|
|CSS String |<div style="width: USER-CONTROLLED-DATA;">Selection</div>| `Encode.forCssString`|
|
||||||
|CSS URL| <div style="background: USER-CONTROLLED-DATA "> |`Encode.forCssUrl`|
|
|CSS URL| <div style="background: USER-CONTROLLED-DATA "> |`Encode.forCssUrl`|
|
||||||
|JavaScript Block |<script>alert("USER-CONTROLLED-DATA")</script>| `Encode.forJavaScriptBlock`|
|
|JavaScript Block |<script>alert("USER-CONTROLLED-DATA")</script>| `Encode.forJavaScriptBlock`|
|
||||||
|JavaScript Variable |<button onclick="alert('USER-CONTROLLED-DATA');">click me</button> |`Encode.forJavaScriptVariable`|
|
|JavaScript Variable |<button onclick="alert('USER-CONTROLLED-DATA');">click me</button> |`Encode.forJavaScriptVariable`|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue