<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>HTML Entity on 보안 연구 노트</title><link>https://blog.mingon.dev/tags/html-entity/</link><description>Recent content in HTML Entity on 보안 연구 노트</description><generator>Hugo -- gohugo.io</generator><language>ko-KR</language><lastBuildDate>Fri, 05 Jun 2026 15:00:00 +0900</lastBuildDate><atom:link href="https://blog.mingon.dev/tags/html-entity/index.xml" rel="self" type="application/rss+xml"/><item><title>[Write-up] PortSwigger - Stored XSS into onclick event with angle brackets and double quotes HTML-encoded and single quotes and backslash escaped</title><link>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---stored-xss-into-onclick-event-with-angle-brackets-and-double-quotes-html-encoded-and-single-quotes-and-backslash-escaped/</link><pubDate>Fri, 05 Jun 2026 15:00:00 +0900</pubDate><guid>https://blog.mingon.dev/write-up/portswigger/xss/write-up-portswigger---stored-xss-into-onclick-event-with-angle-brackets-and-double-quotes-html-encoded-and-single-quotes-and-backslash-escaped/</guid><description>댓글 Website 값이 onclick의 JavaScript 문자열에도 삽입되는 지점에서 HTML 엔티티 디코딩을 이용해 이스케이프를 우회하는 Stored XSS 풀이</description></item></channel></rss>