cleaning up a bit
git-svn-id: http://webgoat.googlecode.com/svn/trunk@255 4033779f-a91e-0410-96ef-6bf7bf53c507
This commit is contained in:
@ -36,7 +36,15 @@ function makeXHR(method, url, parameters) {
|
||||
//alert('status: ' + status);
|
||||
//alert('responseText: ' + responseText);
|
||||
|
||||
eval(http_request.responseText);
|
||||
eval(http_request.responseText);
|
||||
|
||||
if(responseText.indexOf("');") != -1
|
||||
&& responseText.indexOf("alert") != -1
|
||||
&& responseText.indexOf("document.cookie") != -1){
|
||||
|
||||
document.form.submit();
|
||||
}
|
||||
|
||||
}
|
||||
};
|
||||
|
||||
|
Reference in New Issue
Block a user