Chars in href that will not default to full URL
⚠ Browser differences
test
Created byjoaxcar
Created Nov 16, 2024
Updated May 27, 2025
Detecting browser...
CategoryURL Handling
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="$[data1]<>";window.a.href.includes("http") ? false : log("$[data1]")</script>Sample payloads
<base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="á<>";window.a.href.includes("http") ? false : alert("á")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="Ă<>";window.a.href.includes("http") ? false : alert("Ă")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="ă<>";window.a.href.includes("http") ? false : alert("ă")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="∾<>";window.a.href.includes("http") ? false : alert("∾")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="∿<>";window.a.href.includes("http") ? false : alert("∿")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="∾̳<>";window.a.href.includes("http") ? false : alert("∾̳")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="Â<>";window.a.href.includes("http") ? false : alert("Â")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="â<>";window.a.href.includes("http") ? false : alert("â")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="´<>";window.a.href.includes("http") ? false : alert("´")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="А<>";window.a.href.includes("http") ? false : alert("А")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="а<>";window.a.href.includes("http") ? false : alert("а")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="Æ<>";window.a.href.includes("http") ? false : alert("Æ")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="æ<>";window.a.href.includes("http") ? false : alert("æ")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="⁡<>";window.a.href.includes("http") ? false : alert("⁡")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="𝔄<>";window.a.href.includes("http") ? false : alert("𝔄")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="𝔞<>";window.a.href.includes("http") ? false : alert("𝔞")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="À<>";window.a.href.includes("http") ? false : alert("À")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="à<>";window.a.href.includes("http") ? false : alert("à")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="ℵ<>";window.a.href.includes("http") ? false : alert("ℵ")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="ℵ<>";window.a.href.includes("http") ? false : alert("ℵ")</script>Fuzz results
Chrome 146.0.0.0 desktop Windows NT 10.0
Updated12 Mar 2026
Found 2124 results
Loading...
Chrome 145.0.0.0 desktop macOS 10.15.7older version
Updated17 Feb 2026
Found 2124 results
Loading...
Firefox 148.0 desktop Windows NT 10.0
Updated23 Feb 2026
Found 1 result
Loading...
Microsoft Edge 145.0.0.0 desktop Windows NT 10.0
Updated18 Feb 2026
Found 2124 results
Loading...