As a pentester I came across this scenario:
<script type="text/javascript">
URL = 'http://example.com?x=input';
I am able to insert a new line with %A0
, spaces and almost anything except '
. The problem is that I need that '
before making a new line so the JS doesn't break.
I am able to leave it like this:
<script type="text/javascript">
URL = 'http://example.com?x=input;
prompt`9`
anything';
After the input and before the ;
I need to insert a '
or it won't work... Is there any workaround/bypass on this? I am able to inset /
too.