Vuln-Code 1 {JS}
This code series is from "Security explained by Harsh Bothra" vulnerable code:
Code
<script>
<%
String searchTxt = StringEscapeUtils.escape.Html4(request.getParameter("Search"));
%>
document.cookie = 'search=<%searchTxt%>';
</script>Vulnerability
Remedy:
String searchTxt = StringEscapeUtils.escapeHtml4(request.getParameter("search")).replace("'","'");Last updated