Valid characters before domain 1

Import from old 1

Created by: avlidienbrunn

Created on: Wednesday, April 10, 2024 at 8:21:32 AM

Updated on: Thursday, July 25, 2024 at 1:27:39 AM

Vector type: XSS

Template used:
<a href="https://$[chr]example.com/" id="test$[i]"></a>
Code used after fuzz:
if(document.getElementById("test$[i]").host=="example.com"){log($[i])}
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...

Sample payloads

<a href="https://	example.com/" id="test9"></a>
<a href="https://
example.com/" id="test10"></a>
<a href="https://
example.com/" id="test13"></a>
<a href="https:///example.com/" id="test47"></a>
<a href="https://@example.com/" id="test64"></a>
<a href="https://\example.com/" id="test92"></a>
<a href="https://­example.com/" id="test173"></a>
<a href="https://͏example.com/" id="test847"></a>
<a href="https://᠋example.com/" id="test6155"></a>
<a href="https://᠌example.com/" id="test6156"></a>
<a href="https://᠍example.com/" id="test6157"></a>
<a href="https://᠏example.com/" id="test6159"></a>
<a href="https://​example.com/" id="test8203"></a>
<a href="https://⁠example.com/" id="test8288"></a>
<a href="https://⁤example.com/" id="test8292"></a>
<a href="https://︀example.com/" id="test65024"></a>
<a href="https://︁example.com/" id="test65025"></a>
<a href="https://︂example.com/" id="test65026"></a>
<a href="https://︃example.com/" id="test65027"></a>
<a href="https://︄example.com/" id="test65028"></a>

Fuzz results

Chrome logo
Chrome 123.0.6312.52 Unknown Unknown
Found 32 results
DecHexChr
909HT
DecHexChr
100aLF
DecHexChr
130dCR
DecHexChr
472f/
DecHexChr
6440@
DecHexChr
925c\
DecHexChr
173ad­
DecHexChr
84734f͏
DecHexChr
6155180b
DecHexChr
6156180c
DecHexChr
6157180d
DecHexChr
6159180f
DecHexChr
8203200b
DecHexChr
82882060
DecHexChr
82922064
DecHexChr
65024fe00
DecHexChr
65025fe01
DecHexChr
65026fe02
DecHexChr
65027fe03
DecHexChr
65028fe04
DecHexChr
65029fe05
DecHexChr
65030fe06
DecHexChr
65031fe07
DecHexChr
65032fe08
DecHexChr
65033fe09
DecHexChr
65034fe0a
DecHexChr
65035fe0b
DecHexChr
65036fe0c
DecHexChr
65037fe0d
DecHexChr
65038fe0e
DecHexChr
65039fe0f
DecHexChr
65279feff
Firefox logo
Firefox 124.0 Unknown Unknown
Found 32 results
DecHexChr
909HT
DecHexChr
100aLF
DecHexChr
130dCR
DecHexChr
472f/
DecHexChr
6440@
DecHexChr
925c\
DecHexChr
173ad­
DecHexChr
84734f͏
DecHexChr
6155180b
DecHexChr
6156180c
DecHexChr
6157180d
DecHexChr
6159180f
DecHexChr
8203200b
DecHexChr
82882060
DecHexChr
82922064
DecHexChr
65024fe00
DecHexChr
65025fe01
DecHexChr
65026fe02
DecHexChr
65027fe03
DecHexChr
65028fe04
DecHexChr
65029fe05
DecHexChr
65030fe06
DecHexChr
65031fe07
DecHexChr
65032fe08
DecHexChr
65033fe09
DecHexChr
65034fe0a
DecHexChr
65035fe0b
DecHexChr
65036fe0c
DecHexChr
65037fe0d
DecHexChr
65038fe0e
DecHexChr
65039fe0f
DecHexChr
65279feff
Safari logo
Safari 17.4 Unknown Unknown
Found 32 results
DecHexChr
909HT
DecHexChr
100aLF
DecHexChr
130dCR
DecHexChr
472f/
DecHexChr
6440@
DecHexChr
925c\
DecHexChr
173ad­
DecHexChr
84734f͏
DecHexChr
6155180b
DecHexChr
6156180c
DecHexChr
6157180d
DecHexChr
6159180f
DecHexChr
8203200b
DecHexChr
82882060
DecHexChr
82922064
DecHexChr
65024fe00
DecHexChr
65025fe01
DecHexChr
65026fe02
DecHexChr
65027fe03
DecHexChr
65028fe04
DecHexChr
65029fe05
DecHexChr
65030fe06
DecHexChr
65031fe07
DecHexChr
65032fe08
DecHexChr
65033fe09
DecHexChr
65034fe0a
DecHexChr
65035fe0b
DecHexChr
65036fe0c
DecHexChr
65037fe0d
DecHexChr
65038fe0e
DecHexChr
65039fe0f
DecHexChr
65279feff