<?xml version="1.0" encoding="UTF-8"?>
<rss version="0.91">
<channel>
  <title>Test XSS in RSS</title>
  <link>http://tungwaiyip.info/</link>
  <description>Test XSS in RSS feeder</description>
  <language>en-us</language>
  <item>
    <title><![CDATA[<script>function a() { alert("Gotcha!"); }</script>Click <a href="javascript:a()">here</a>]]></title>
    <description>Trick in title</description>
    <link>http://tungwaiyip.info</link>
    <pubDate>Fri, 21 Nov 2003 15:01:00 EST</pubDate>
  </item>
  <item>
    <title>Trick in description</title>
    <description><![CDATA[<script>function a() { alert("Gotcha!"); }</script>Click <a href="javascript:a()">here</a>]]></description>
    <link>http://tungwaiyip.info</link>
    <pubDate>Fri, 21 Nov 2003 15:01:00 EST</pubDate>
  </item>
  <item>
    <title>Trick in description inside href attribute</title>
    <description><![CDATA[Click <a href='javascript:alert("Gotcha!");'>here2</a>]]></description>
    <link>http://tungwaiyip.info</link>
    <pubDate>Fri, 21 Nov 2003 15:01:00 EST</pubDate>
  </item>
  <item>
    <title><![CDATA[meta charactes <>&'"]]></title>
    <description><![CDATA[meta charactes <>&'"]]></description>
    <link>http://tungwaiyip.info</link>
    <pubDate>Fri, 21 Nov 2003 15:01:00 EST</pubDate>
  </item>
</channel>
</rss>
