Important information
Our challenges do NOT require any bruteforcing/directory fuzzing/massive amounts of traffic. Please practise hacking on our challenges manually.
Failure to abide by the rules will put you at risk of being restricted from using our free challenges.
This strict URL filter should prevent XSS, right?
                      Medium
                    Cross Site Scripting (XSS)
            
                   
This one is pretty simple. One parameter is vulnerable, ?url=. Can you get XSS to execute?
Completed the challenge?
You can browse the intended solution to this challenge below.
 
   Getting started
 Getting started Learn about vulnerability types
 Learn about vulnerability types  Getting started in bug bounties
 Getting started in bug bounties  Test your knowledge
 Test your knowledge Free Web Application Challenges
 Free Web Application Challenges Guides for your hunts
 Guides for your hunts  ZSeano's Methodology
  ZSeano's Methodology Effective Note Taking for bug bounties
 Effective Note Taking for bug bounties Useful Resources
 Useful Resources  Disclosed HackerOne Reports
  Disclosed HackerOne Reports  Our community
 Our community Endorsed Members
 Endorsed Members Hackevents
  Hackevents  Member Articles
 Member Articles