A space makes all the difference
Thursday, January 1st, 1970r0xes had an interesting XSS vulnerability posted to Bugtraq yesterday where he was able to bypass some XSS filters by simply adding a space between the event handler and the equals sign. It’s simple enough but hey, anything that gets around filters is worth noting. Regex is often very flawed.


