← ChallengesEasyreflected0/13 solved
mission · xss-reflected-filtered

The Script Filter

HackerMart heard about the last finding and added a quick fix: they now strip the literal word `<script>` from search input. Most payloads are dead on arrival… but only the ones they thought of.

objective

Fire an alert box even though `<script>` tags are stripped.

🔒
HackerMartHomeShopSearchcart · 0
Search HackerMart

Find a product in our catalog.

Simulated target for training. This page is the vulnerable website — payloads you craft execute here in your browser. Practice only on systems you own or are authorized to test.