Entities still parsed in uppercase

Safari logo 35
Chrome logo 35
Firefox logo 35

This vector transforms each entity into uppercase and checks if it is still rendered.

Created by: hackvertor

Created on: Tuesday, July 2, 2024 at 5:15:34 PM

Updated on: Wednesday, January 15, 2025 at 3:16:08 AM

Vector type: JS

Vector charset: UTF-8

Code used before fuzz:
const div = document.createElement('div');
Template used:
let entity = '$[data1]'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '$[data1]') {
   log(entity);
}
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...

Sample payloads

let entity = '&'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&') {
   alert(entity);
}
let entity = '©'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '©') {
   alert(entity);
}
let entity = '&COPYSR;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&COPYSR;') {
   alert(entity);
}
let entity = 'ⅅ'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== 'ⅅ') {
   alert(entity);
}
let entity = 'Ŋ'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== 'Ŋ') {
   alert(entity);
}
let entity = 'Ð'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== 'Ð') {
   alert(entity);
}
let entity = '&GTCC;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTCC;') {
   alert(entity);
}
let entity = '&GTCIR;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTCIR;') {
   alert(entity);
}
let entity = '>'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '>') {
   alert(entity);
}
let entity = '&GTDOT;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTDOT;') {
   alert(entity);
}
let entity = '&GTLPAR;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTLPAR;') {
   alert(entity);
}
let entity = '&GTQUEST;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTQUEST;') {
   alert(entity);
}
let entity = '&GTRAPPROX;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTRAPPROX;') {
   alert(entity);
}
let entity = '&GTRARR;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTRARR;') {
   alert(entity);
}
let entity = '&GTRDOT;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTRDOT;') {
   alert(entity);
}
let entity = '&GTREQLESS;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTREQLESS;') {
   alert(entity);
}
let entity = '&GTREQQLESS;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTREQQLESS;') {
   alert(entity);
}
let entity = '&GTRLESS;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTRLESS;') {
   alert(entity);
}
let entity = '&GTRSIM;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&GTRSIM;') {
   alert(entity);
}
let entity = '&LTCC;'.toUpperCase();
div.innerHTML= entity;
if(!div.innerText.includes(entity) && entity !== '&LTCC;') {
   alert(entity);
}

Fuzz results

Safari logo
Safari 17.5 mobile iOS 17.5.1

Updated

Tue Jul 02 2024
Found 35 results
Loading...
Chrome logo
Chrome 126.0.0.0 desktop macOS 10.15.7

Updated

Tue Jul 02 2024
Found 35 results
Loading...
Safari logo
Safari 17.4 desktop macOS 10.15.7

Updated

Tue Jul 02 2024
Found 35 results
Loading...
Firefox logo
Firefox 127.0 desktop macOS 10.15

Updated

Tue Jul 02 2024
Found 35 results
Loading...