
Ruth Bergman
Everything here is written for whoever has to make the repair. A payload on its own helps nobody and teaches less and hands a stranger a working exploit, so each example pairs the input with the output it produced and a fix you can apply to your own code. Output context decides everything about XSS. A string placed in an HTML body, inside a quoted attribute, inside a script block and inside a URL each need different escaping, and encoding written for one context is useless or dangerous in another. That is why sanitiser lists get confused: a library excellent at HTML does nothing for a JavaScript context, and allowing a few extra tags to permit an attribute carrying an event handler reintroduces the bug it was meant to remove. SQL injection reduces to one rule: bind parameters, never concatenate. Identifiers such as table names cannot be bound, which is why a sort column often ends up interpolated, and that is where second and third-order problems live. I keep defences layered rather than singular. Encoding stops the immediate bug. A Content Security Policy limits what happens when something slips through. Neither replaces the other, and both are presented that way. A page about third-party script tags is a page about trust, because a script from another domain executes with full privileges on your page and no amount of output encoding in your own templates stops it. I also spend time on what happens after a fix lands, because a vulnerable component in a dependency behaves nothing like a vulnerable line of your own code. The report, the disclosure timeline and the credit line are all part of the job, and I would rather explain a slow patch than help somebody skip a verification step.
About ToolSura
ToolSura offers 80+ free, privacy-first online tools that run 100% in your browser — no uploads, no logins. Learn more about our mission →