Xss
Eventless
by YesWeHack
drag_indicator
drag_indicator
drag_indicator
Another way
This time both "script" and JavaScript events are blacklisted. But there is still another way to trigger JS execution.
Goal: alert(flag)
Hints
Solution
drag_indicator
INPUT
OUTPUT
drag_indicator
drag_indicator