OLD | NEW |
1 <!DOCTYPE html> | 1 <!DOCTYPE html> |
2 <html> | 2 <html> |
3 <head> | 3 <head> |
4 <script> | 4 <script> |
5 if (window.testRunner) { | 5 if (window.testRunner) { |
6 testRunner.dumpAsText(); | 6 testRunner.dumpAsText(); |
7 testRunner.dumpChildFramesAsText(); | 7 testRunner.dumpChildFramesAsText(); |
8 testRunner.waitUntilDone(); | 8 testRunner.waitUntilDone(); |
9 testRunner.setXSSAuditorEnabled(true); | 9 testRunner.setXSSAuditorEnabled(true); |
10 } | 10 } |
11 </script> | 11 </script> |
12 </head> | 12 </head> |
13 <body> | 13 <body> |
14 <p>This test passes if the element displayed in the frame below has a 'value
s' attribute containing only 'javascript:void(0)'.</p> | 14 <p>This test passes if the element displayed in the frame below has a 'value
s' attribute containing only 'javascript:void(0)'.</p> |
15 <iframe src="http://localhost:8000/security/xssAuditor/resources/echo-intert
ag.pl?q=<svg%20xmlns:xlink='http://www.w3.org/1999/xlink'><a><circle%20r=100%20/
><animate%20attributeName=xlink:href%20values=javascript%3Aalert(1)%3B%3B&clutte
r=blah'>¬ifyDone=1&dumpElementBySelector=animate"></iframe> | 15 <iframe src="http://localhost:8000/security/xssAuditor/resources/echo-intert
ag.pl?q=<svg><a><circle%20r=100%20/><animate%20attributeName=href%20values=%3Bja
vascript%3Aalert(1)%20begin=0s%20end=0.1s%20fill=freeze%20/></a></svg>¬ifyDon
e=1&dumpElementBySelector=animate"></iframe> |
16 </body> | 16 </body> |
17 </html> | 17 </html> |
OLD | NEW |