|
|
|
|
@ -17,6 +17,7 @@ unsafe_tests = [
|
|
|
|
|
'<META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(999);">',
|
|
|
|
|
'<IFRAME SRC="javascript:alert(999);"></IFRAME>',
|
|
|
|
|
'<IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>',
|
|
|
|
|
'<style type="text/css">div.foo { background: #ffff; }</style>',
|
|
|
|
|
'<EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>',
|
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
|