 Chromium Code Reviews
 Chromium Code Reviews Issue 205243002:
  XSSAuditor bypass with script tag and expression following injection point  (Closed) 
  Base URL: svn://svn.chromium.org/blink/trunk
    
  
    Issue 205243002:
  XSSAuditor bypass with script tag and expression following injection point  (Closed) 
  Base URL: svn://svn.chromium.org/blink/trunk| Index: LayoutTests/http/tests/security/xssAuditor/script-tag-near-start-expected.txt | 
| diff --git a/LayoutTests/http/tests/security/xssAuditor/script-tag-near-start-expected.txt b/LayoutTests/http/tests/security/xssAuditor/script-tag-near-start-expected.txt | 
| new file mode 100644 | 
| index 0000000000000000000000000000000000000000..c513aa09b95fee2c9e19f2adca4df22192b32d72 | 
| --- /dev/null | 
| +++ b/LayoutTests/http/tests/security/xssAuditor/script-tag-near-start-expected.txt | 
| @@ -0,0 +1,2 @@ | 
| +CONSOLE ERROR: line 5: The XSS Auditor refused to execute a script in 'http://localhost:8000/security/xssAuditor/resources/echo-intertag.pl?script-expression-follows=1&q=%3Cscript%3E%22%3Cscript%3E%22-alert(/XSS/)' because its source code was found within the request. The auditor was enabled as the server sent neither an 'X-XSS-Protection' nor 'Content-Security-Policy' header. | 
| + |