Re: Removing unwanted inject script

  •  06-04-2007, 2:14 PM

    Re: Removing unwanted inject script

    Thank you Adam for fixing that issue. But I am still having issues with inject script.  It works ok if you switch between normal and HTML modes, but if you click the submit in your sample page it does not get stripped out.
     
    Go to the sample page, switch to HTML mode, type the following
     
    <iframe onload="BLOCKED SCRIPTalert('proof of concept')"></iframe>
     
    Click submit and it will not strip out the offending code.
     
    Jason
View Complete Thread