Collected research
Twitter misidentifying context
Escaping quotes is not enough inside a JavaScript event attribute, because HTML entities are decoded before the script runs. Twitter escaped the literal quote characters in an onclick handler, but the named and numeric entity spellings of an apostrophe, including unterminated ones, still closed the string and injected code. Escape entities too, using hex escapes.
Record
- Researcher
- Gareth Heyes
- Published by
- thespanner.co.uk
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .