XSS (Cross-Site Scripting)

XSS in HTML attributes

Medium
45 min

This module is used to practice identifying and exploiting XSS vulnerabilities. Read the assignment and use the skills learned in previous modules to solve the task.

XSS UNQUOTED 1

In this task, we exploit the XSS vulnerability in an application that does not use apostrophes to define HTML attributes.

Objective

Capture the administrator session.

Exercises

Flag

Find the flag from the lab environment and enter it below.

With the search below, you can execute JavaScript code.

search onfocus=alert(1) autofocus

Find out the cause of the XSS vulnerability, build the final payload and use it as required.

hakatemia pro

Ready to become an ethical hacker?
Start today.

As a member of Hakatemia you get unlimited access to Hakatemia modules, exercises and tools, and you get access to the Hakatemia Discord channel where you can ask for help from both instructors and other Hakatemia members.