diff options
author | Philipp Hagemeister <phihag@phihag.de> | 2013-02-05 18:50:21 +0100 |
---|---|---|
committer | Philipp Hagemeister <phihag@phihag.de> | 2013-02-05 18:50:21 +0100 |
commit | f608517d9e1dee126431aafedabdabaa03ec2937 (patch) | |
tree | d3f60375488b2d63bac3d24b0a41d1af3073e213 /tests | |
parent | c201f3c706316fbafff51631ce86a0a3784f3218 (diff) | |
download | markdown-f608517d9e1dee126431aafedabdabaa03ec2937.tar.gz markdown-f608517d9e1dee126431aafedabdabaa03ec2937.tar.bz2 markdown-f608517d9e1dee126431aafedabdabaa03ec2937.zip |
Forbid javascript:// URLs in safe mode
Diffstat (limited to 'tests')
-rw-r--r-- | tests/safe_mode/link-targets.html | 2 | ||||
-rw-r--r-- | tests/safe_mode/link-targets.txt | 3 |
2 files changed, 5 insertions, 0 deletions
diff --git a/tests/safe_mode/link-targets.html b/tests/safe_mode/link-targets.html new file mode 100644 index 0000000..768ae5b --- /dev/null +++ b/tests/safe_mode/link-targets.html @@ -0,0 +1,2 @@ +<p><a href="">XSS</a> +See http://security.stackexchange.com/q/30330/1261 for details.</p>
\ No newline at end of file diff --git a/tests/safe_mode/link-targets.txt b/tests/safe_mode/link-targets.txt new file mode 100644 index 0000000..10eebda --- /dev/null +++ b/tests/safe_mode/link-targets.txt @@ -0,0 +1,3 @@ +[XSS](javascript://%0Aalert%28'XSS'%29;) +See http://security.stackexchange.com/q/30330/1261 for details. + |