Replies: 1 comment
-
Hi @Tamil-dev e.g
For example, you could attack like this. var a = alert(document.location.href) It's hard to make it an PoC because I don't know your response data. Either way, dalfox wrote data in the JS area, which means that JavaScript is likely to be available. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
inJS-none :(
Beta Was this translation helpful? Give feedback.
All reactions