Characters that can be inserted in the middle of the JS protocol name
/
Created by: Rachid.A
Created on: 4/15/2024, 1:45:27 AM
Updated on: 5/8/2024, 6:55:32 AM
Vector type: XSS
Template used:
<a id="0" href="j$[chr]avas$[chr]crip$[chr]t:window">craft-me</a>
Code used after fuzz:
if (document.getElementById("0").protocol === "javascript:") { log($[i]) }
Your browser was detected as:
Detecting... Detecting...
Fuzz results:
Chrome 123.0.0.0
Results
Found 3
Dec | Hex | Chr |
---|---|---|
9 | 09 | HT |
Dec | Hex | Chr |
---|---|---|
10 | 0a | LF |
Dec | Hex | Chr |
---|---|---|
13 | 0d | CR |
Firefox 124.0
Results
Found 3
Dec | Hex | Chr |
---|---|---|
9 | 09 | HT |
Dec | Hex | Chr |
---|---|---|
10 | 0a | LF |
Dec | Hex | Chr |
---|---|---|
13 | 0d | CR |
Safari 15.5
Results
Found 3
Dec | Hex | Chr |
---|---|---|
9 | 09 | HT |
Dec | Hex | Chr |
---|---|---|
10 | 0a | LF |
Dec | Hex | Chr |
---|---|---|
13 | 0d | CR |