case, then you need to test the filter to establish whether any bypasses exist.
The bypasses that are commonly found in real-world XSS filters include the
following:
■■
Many filters match specific tags, including the opening and closing
angle brackets. However, most browsers tolerate whitespace before the
closing bracket, which allows an easy bypass of the filter. For example:
Do'stlaringiz bilan baham: