Lab: DOM XSS in
document.write sink using source
location.search inside a select element
document.write function, which writes data out to the page. The
document.write function is called with data from
location.search which you can control using the website URL. The data is enclosed within a select element.
To solve this lab, perform a cross-site scripting attack that breaks out of the select element and calls the
Use Burp Suite to intercept and modify the request to the stock checking function, containing the
Enter a random alphanumeric string into the
- Right-click and inspect the element, and observe that your random string has been placed inside a select element.
Change the URL to: