. [normal link](javascript) .

normal link

. Should not allow some protocols in links and images . [xss link](javascript:alert(1)) .

[xss link](javascript:alert(1))

. . [xss link](JAVASCRIPT:alert(1)) .

[xss link](JAVASCRIPT:alert(1))

. . [xss link](vbscript:alert(1)) .

[xss link](vbscript:alert(1))

. . [xss link](VBSCRIPT:alert(1)) .

[xss link](VBSCRIPT:alert(1))

. . [xss link](file:///123) .

[xss link](file:///123)

. . [xss link]("><script>alert("xss")</script>) .

xss link

. Image parser use the same code base. . ![xss link](javascript:alert(1)) .

![xss link](javascript:alert(1))

.