I think I know what you mean now - like a sneaky javascript URL or something?
P.S: Ah - so it only insterts the space if the "javascript" is in quotes... got it.
P.P.S: I wonder if single quotes catch it out or not... testing: 'javascript'...
P.P.P.S: No - that doesn't get filtered through - very weird... must only happen occasionally; ie it's not 100% js exploit-proof?




Reply With Quote