OLD | NEW |
1 CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://lo
calhost:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Csvg%20xmlns:xli
nk=%27http://www.w3.org/1999/xlink%27%3E%3Ca%3E%3Ccircle%20r=100%20/%3E%3Canimat
e%20attributeName=xlink:href%20values=%3Bjavascript%3Aalert(1)%3B&clutter=blah%2
7%3E¬ifyDone=1&dumpElementBySelector=animate' because its source code was fou
nd within the request. The auditor was enabled as the server sent neither an 'X-
XSS-Protection' nor 'Content-Security-Policy' header. | 1 CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://lo
calhost:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Csvg%20xmlns:xli
nk=%27http://www.w3.org/1999/xlink%27%3E%3Ca%3E%3Ccircle%20r=100%20/%3E%3Canimat
e%20attributeName=xlink:href%20values=%3Bjavascript%3Aalert(1)%3B&clutter=blah%2
7%3E¬ifyDone=1&dumpElementBySelector=animate' because its source code was fou
nd within the request. The auditor was enabled as the server sent neither an 'X-
XSS-Protection' nor 'Content-Security-Policy' header. |
2 CONSOLE WARNING: SVG's SMIL animations (<animate>, <set>, etc.) are deprecated a
nd will be removed. Please use CSS animations or Web animations instead. | |
3 This test passes if the element displayed in the frame below has a 'values' attr
ibute containing only 'javascript:void(0)'. | 2 This test passes if the element displayed in the frame below has a 'values' attr
ibute containing only 'javascript:void(0)'. |
4 | 3 |
5 | 4 |
6 | 5 |
7 -------- | 6 -------- |
8 Frame: '<!--framePath //<!--frame0-->-->' | 7 Frame: '<!--framePath //<!--frame0-->-->' |
9 -------- | 8 -------- |
10 animate => animate | 9 animate => animate |
11 * attributeName: xlink:href | 10 * attributeName: xlink:href |
12 * values: javascript:void(0) | 11 * values: javascript:void(0) |
13 Page rendered here. | 12 Page rendered here. |
OLD | NEW |