Characters allowed before event in attribute name using setAttribute
This vector shows which characters are allowed before an event name when using setAttribute.
Created by: hackvertor
Created on: Wednesday, August 21, 2024 at 11:46:45 AM
Updated on: Monday, September 2, 2024 at 4:58:09 PM
Vector type: JS
Template used:
let img = document.createElement('img');
img.src = 'data:';
img.setAttribute('$[chr]onerror','log($[i])')
document.body.append(img);
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...
Sample payloads
let img = document.createElement('img');
img.src = 'data:';
img.setAttribute('\onerror','alert(92)')
document.body.append(img);
Fuzz results
Chrome 127.0.0.0 desktop macOS 10.15.7
Found 1 result
Dec | Hex | Chr |
---|---|---|
92 | 5c | \ |
Firefox 129.0 desktop macOS 10.15
Found 1 result
Dec | Hex | Chr |
---|---|---|
92 | 5c | \ |
Safari 18.0 desktop macOS 10.15.7
Found 1 result
Dec | Hex | Chr |
---|---|---|
92 | 5c | \ |