<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=XSS_Experimental_Minimal_Encoding_Rules</id>
		<title>XSS Experimental Minimal Encoding Rules - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=XSS_Experimental_Minimal_Encoding_Rules"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=XSS_Experimental_Minimal_Encoding_Rules&amp;action=history"/>
		<updated>2026-05-03T02:17:27Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=XSS_Experimental_Minimal_Encoding_Rules&amp;diff=135930&amp;oldid=prev</id>
		<title>Jmanico: Created page with &quot;The following examples demonstrate experimental minimal encoding rules for XSS prevention.   {| class=&quot;wikitable nowraplinks&quot; |- ! Context ! Code Sample ! Rules |- | JavaScrip...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=XSS_Experimental_Minimal_Encoding_Rules&amp;diff=135930&amp;oldid=prev"/>
				<updated>2012-09-16T17:46:25Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;The following examples demonstrate experimental minimal encoding rules for XSS prevention.   {| class=&amp;quot;wikitable nowraplinks&amp;quot; |- ! Context ! Code Sample ! Rules |- | JavaScrip...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The following examples demonstrate experimental minimal encoding rules for XSS prevention. &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable nowraplinks&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Context&lt;br /&gt;
! Code Sample&lt;br /&gt;
! Rules&lt;br /&gt;
|-&lt;br /&gt;
| JavaScript, quoted string in a script block&lt;br /&gt;
| &amp;amp;lt;script&amp;gt;alert(&amp;quot;Hello &amp;quot;+&amp;quot;&amp;amp;lt;%= &amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt; %&amp;gt;&amp;quot;);&amp;amp;lt;/script&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Use these escapes: \\ \r \n \b \t \f \' \&amp;quot; \/&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;For any other character in range 0..0x19, use hex escapes&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;If using non-Unicode charset, any character above 0x7e, use '\u' encoding&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| JavaScript, quoted string in an event handler attribute&lt;br /&gt;
| onclick=&amp;quot;alert('&amp;lt;%= &amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt; %&amp;gt;')&amp;quot;;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Use these escapes: \\ \r \n \b \t \f&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Use hex escapes for these characters: ' &amp;quot; &amp;amp;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;For any other character in range 0..0x19, use hex escapes&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;If using non-Unicode charset, any character above 0x7e, use '\u' encoding&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| HTML Body (up to HTML 4.01):&lt;br /&gt;
| &amp;amp;lt;div&amp;gt;&amp;lt;%= &amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt; %&amp;gt;&amp;amp;lt;/div&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;HTML Entity encode &amp;amp;lt; &amp;amp;amp;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;specify charset in metatag to avoid UTF7 XSS&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;b&amp;gt;X&amp;lt;/b&amp;gt;HTML Body:&lt;br /&gt;
| &amp;amp;lt;div&amp;gt;&amp;lt;%= &amp;lt;span style=&amp;quot;color:red;&amp;quot;&amp;gt;UNTRUSTED DATA&amp;lt;/span&amp;gt; %&amp;gt;&amp;amp;lt;/div&amp;gt;&lt;br /&gt;
| &amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;HTML Entity encode &amp;amp;lt; &amp;amp;amp; &amp;amp;gt;&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;limit input to charset http://www.w3.org/TR/2008/REC-xml-20081126/#charsets&amp;lt;/li&amp;gt;&amp;lt;/ul&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Jmanico</name></author>	</entry>

	</feed>