mirror of
https://github.com/Lastorder-DC/rhymix.git
synced 2026-05-08 19:42:15 +09:00
Move upload file filter to Rhymix Framework and add proper unit tests for SVG-based attacks
This commit is contained in:
parent
af64ae79c1
commit
e98cf03d95
6 changed files with 250 additions and 126 deletions
8
tests/_data/security/xss.svg
Normal file
8
tests/_data/security/xss.svg
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
<?xml version="1.0" standalone="no"?>
|
||||
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
|
||||
<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg">
|
||||
<polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
|
||||
<script type="text/javascript">
|
||||
alert('XSS');
|
||||
</script>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 364 B |
Loading…
Add table
Add a link
Reference in a new issue