From 5e60cb83de861a46ed18a27a62b6720f3dd341f0 Mon Sep 17 00:00:00 2001 From: rubenwardy Date: Wed, 22 Jan 2020 23:45:40 +0000 Subject: [PATCH] Add XSS strings to test data --- app/default_data.py | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/app/default_data.py b/app/default_data.py index 85f42b32..eb8aec6f 100644 --- a/app/default_data.py +++ b/app/default_data.py @@ -304,6 +304,38 @@ No warranty is provided, express or implied, for any part of the project. game1.desc = """ As seen on the Capture the Flag server (minetest.rubenwardy.com:30000) +` `[`javascript:/*-->` + + + + + +```` + +\xxs link\ + +\xxs link\ + + + + + +`](http://xss.rocks/xss.js%3E%3C/SCRIPT%3E)`;` + +`` + + + + + + + +"\> + Uses the CTF PvP Engine. """