The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab - Reflected XSS into HTML context with most tags and attributes blocked

nicchongwb | Last updated: Jun 18, 2021 09:09AM UTC

I tried the following payload and delivering it to exploit server and victim and it is not working. Is there anything that I am missing out or is this a bug in the lab? Thankyou Following payload: <iframe src="https://labid/?search=%22%3C%3Ebody%20onresize=alert(document.cookie)%3E%20onload=this.style.width='100px'"

Ben, PortSwigger Agent | Last updated: Jun 18, 2021 12:56PM UTC