As per usual, there are solutions for all challenges
Can you get the page to calculate 7*7 and output 49 all on it's own?
Can you also get a pop-up? This will require you to escape the sandbox.
This is a simple AngularJS application. The code here is intended to demonstrate input handling. However, there’s a way to trigger a popup using a carefully crafted payload. Can you figure it out? Remember that you cannot use {}
directly but can explore alternatives with urldecode
.
The following block displays the input
parameter without escaping:
This application uses AngularJS for dynamic interaction. Experiment with inputs and payloads!