Description
CWE: 83 Cross Site Scripting (XSS) in attributes; Examples(replace QUOTE with an actual double quote): ?img_loc=http://www.google.comQUOTE%20onerror=QUOTEalert(1) and ?img_loc=http://www.google.comQUOTE%20onerror=QUOTEjavascript:alert(1)
BadSource: File Read data from file (named c:\data.txt)
GoodSource: A hardcoded string
Sinks: printlnServlet
BadSink : XSS in img src attribute
Flow Variant: 21 Control flow: Flow controlled by value of a private variable. All functions contained in one file.
Flaws
Test Suites
Documentation
Have any comments on this test case? Please, send us an email.