I have a input tag like this
<input class="textBox" type="text" value="<%=ESAPI.encoder().canonicalize(query) %>" autocomplete="off" />
I tried using the ESAPI canonicalize function for query like "><script>alert(1);</script>
But it doesnt work and i get alert in my browser. Am i doing it right?