Guest User

Untitled

a guest
Nov 19th, 2017
59
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1. var1=untrusteduserinput
  2.  
  3. <%=server.htmlencode(var1)%>
  4.  
  5. <a href="http://www.example.com/page.asp?var1=<%=server.urlencode(var1)%>"><%=server.htmlencode(var1)%></a>
  6.  
  7. <img src="http://www.example.com/images/<%=server.urlencode(var1)%>" alt="<%=server.htmlencode(var1)%>">
  8.  
  9. <iframe src="http://www.example.com/page.asp?var1=<%=server.urlencode(var1)%>"></iframe>
  10.  
  11. <meta name="description" content="<%=server.htmlencode(var1)%>">
  12.  
  13. <input type="text" name="var1" value="<%=server.htmlencode(var1)%>">
  14.  
  15. <a href="mailto:<%=server.urlencode(var1)%>">Email</a>
  16.  
  17. <a href=”<%=server.urlencode(var1)%>”><%=server.htmlencode(var1)%></a>
  18.  
  19. <a href=”http://www.mypage.com/page.asp?var1=<%=server.urlencode(var1)%>”>
  20.  
  21. <a href="http://www.mypage.com/page.asp?var1=<%= Server.HTMLEncode(Server.URLEncode(var1)) %>">
  22.  
  23. <img src=”http://www.mypage.com/images/<%=server.urlencode(var1)%>”
Add Comment
Please, Sign In to add comment