Vector Created By
XSS Without Space Test 1 @irsdl
script var separator @i_bo0om
Events in tags with src or href that execute javascript @garethheyes
Tags and events that execute javascript 2 @garethheyes
Characters allowed after script @garethheyes
Characters allowed for padding in a data URI 001 @0x6D6172696F
Characters allowed before colon in js url @garethheyes