3 ms·
The <script>alert(“XSS”)</script>
testing https://news.ycombinator.com/item?id=34759951 https://news.ycombinator.com/item?id=34759951
- sotrue5 4y agotest comment
- WantonQuantum 4y agoI'd be surprised if HN were vulnerable to XSS attacks.
- sotrue5 4y agoI would too, but https://news.ycombinator.com/item?id=34759951 https://news.ycombinator.com/item?id=34759951 suggests otherwise.
- sotrue5 4y agosorry for spam @dang
- josephcsible 4y agoThis is bad. I think the only reason it didn't work here is that you used smart quotes instead of straight quotes. Edit: It's completely fixed now.
- thekingshorses 4y agoSeems like it is fixed in a weird way. <marquee>alert("XSS")</marquee>