Featured vector

Chrome 0.0
<!-- sample vector --> <script> alert(1)0x20290x2029 hax</script>

Fuzz vector cloud

3,386,006 Successful fuzzes

Fuzz Database


13.0
Vector Created By
Characters after javascript uri @insertScript
Characters before javascript uri @insertScript
Characters allowed before slashes no protocol @garethheyes
Characters allowed inside slashes no protocol @garethheyes
Characters allowed instead of slash 2 @garethheyes
Characters allowed instead of colon in js url @garethheyes
Replacement for s in script tag @blubbfiction
Replacement for lt in tag @blubbfiction
Entities allowed instead of colon for js protocol @peksa
Entities allowed after js protocol @garethheyes
Entities allowed before js protocol @garethheyes
Entities allowed before CSS rule @garethheyes
Break out of HTML element from single quoted attribute @peksa
Escaped characters that break out of single quote HTML attribute @peksa
Characters that escape single quoted HTML attributes @peksa
Eating backslash @garethheyes
Characters that break out of script variables @garethheyes
Char that allows you to act as a slash in closing tag 2 @notxssninja
Characters that close a HTML comment 3 @DOMXss
Characters that are spaces @garethheyes
Characters that are new lines @garethheyes
Attribute separators @garethheyes
Characters separating attributes without quotes after hash @garethheyes
Characters separating attributes without quotes @garethheyes
Determine what character can be at the end of the javascript but before the colon @MisterJyu
Characters allowed as slash in url @garethheyes
Array variables @garethheyes
Characters that trigger a new attr after new line @garethheyes
Characters eating backslash in javascript string 2 @mhswende
Characters consuming backslashes and breaking JS strings @0x6D6172696F