| OLD | NEW |
| 1 CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://lo
calhost:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Csvg%3E%3Ca%3E%3
Ccircle%20r=100%20/%3E%3Canimate%20attributeName=href%20values=%3Bjavascript%3Aa
lert(1)%20begin=0s%20end=0.1s%20fill=freeze%20/%3E%3C/a%3E%3C/svg%3E¬ifyDone=
1&dumpElementBySelector=animate' because its source code was found within the re
quest. The auditor was enabled as the server did not send an 'X-XSS-Protection'
header. | 1 CONSOLE ERROR: line 4: The XSS Auditor refused to execute a script in 'http://lo
calhost:8000/security/xssAuditor/resources/echo-intertag.pl?q=%3Csvg%3E%3Ca%3E%3
Ccircle%20r=100%20/%3E%3Canimate%20attributeName=href%20values=%3Bjavascript%3Aa
lert(1)%20begin=0s%20end=0.1s%20fill=freeze%20/%3E%3C/a%3E%3C/svg%3E¬ifyDone=
1&dumpElementBySelector=animate' because its source code was found within the re
quest. The server sent an 'X-XSS-Protection' header requesting this behavior. |
| 2 This test passes if the element displayed in the frame below has a 'values' attr
ibute containing only 'javascript:void(0)'. | 2 This test passes if the element displayed in the frame below has a 'values' attr
ibute containing only 'javascript:void(0)'. |
| 3 | 3 |
| 4 | 4 |
| 5 | 5 |
| 6 -------- | 6 -------- |
| 7 Frame: '<!--framePath //<!--frame0-->-->' | 7 Frame: '<!--framePath //<!--frame0-->-->' |
| 8 -------- | 8 -------- |
| 9 animate => animate | 9 animate => animate |
| 10 * attributeName: href | 10 * attributeName: href |
| 11 * values: javascript:void(0) | 11 * values: javascript:void(0) |
| 12 * begin: 0s | 12 * begin: 0s |
| 13 * end: 0.1s | 13 * end: 0.1s |
| 14 * fill: freeze | 14 * fill: freeze |
| 15 Page rendered here. | 15 Page rendered here. |
| OLD | NEW |