Web Hack List

Other nomination

Twitter misidentifying context

Escaping quotes is not enough inside a JavaScript event attribute, because HTML entities are decoded before the script runs. Twitter escaped the literal quote characters in an onclick handler, but the named and numeric entity spellings of an apostrophe, including unterminated ones, still closed the string and injected code. Escape entities too, using hex escapes.

Record

Researcher
Gareth Heyes

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host.