The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Scanner: XSS with percent sign

August | Last updated: Sep 07, 2016 06:49PM UTC

Burp Scanner recently flagged an XSS finding where the injected string was <%MWITE>. Further investigation revealed that the application would also reflect <%script>. Under what circumstances is this actually exploitable? Are there certain browsers that will execute a script tag formed like this?

PortSwigger Agent | Last updated: Sep 08, 2016 08:22AM UTC