Lab has an HTML filter that blocks most onxxx event handlers, but using a really obscure one allows exploitation.
Lab has an HTML filter that blocks most onxxx event handlers, but using a really obscure one allows exploitation.