As a pentester I came across this scenario:
<script type="text/javascript">
URL = 'http://example.com?x=input';
I am able to insert a new line with %A0, spaces and almost anything except '. The problem is that I need that ' before making a new line so the JS doesn't break.
I am able to leave it like this:
<script type="text/javascript">
URL = 'http://example.com?x=input;
prompt`9`
anything';
After the input and before the ; I need to insert a ' or it won't work... Is there any workaround/bypass on this? I am able to inset / too.