From cfce7763f099d7aac5c14905983f61e712db4fea Mon Sep 17 00:00:00 2001 From: Bene-Notebook Date: Tue, 27 Nov 2018 14:48:07 +0100 Subject: [PATCH] Outcommented lines in XSS Lessons 3 that were causing erros --- .../org/owasp/webgoat/plugin/CrossSiteScriptingLesson3.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/CrossSiteScriptingLesson3.java b/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/CrossSiteScriptingLesson3.java index cd95617d9..0c3681fd1 100644 --- a/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/CrossSiteScriptingLesson3.java +++ b/webgoat-lessons/cross-site-scripting/src/main/java/org/owasp/webgoat/plugin/CrossSiteScriptingLesson3.java @@ -37,8 +37,8 @@ public class CrossSiteScriptingLesson3 extends AssignmentEndpoint { //check html string for regex //check for c:out && escapeXml="true" && !request.getParameter - Document doc = Jsoup.parse(editor); - Element e = doc.getElementById(); + //Document doc = Jsoup.parse(editor); + //Element e = doc.getElementById(); System.out.println(editor); if (editor.contains("c:out") && editor.contains("escapeXml=\"true\"") && editor.contains("value=\"${last_name}\"") && editor.contains("value=\"${first_name}\"")) {