Chars in href that will not default to full URL
⚠ Browser differences
test
Created byjoaxcar
Created Nov 16, 2024
Updated May 27, 2025
Detecting browser...
CategoryURL Handling
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="$[data1]<>";window.a.href.includes("http") ? false : log("$[data1]")</script>Sample payloads
<base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="á<>";window.a.href.includes("http") ? false : alert("á")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="Ă<>";window.a.href.includes("http") ? false : alert("Ă")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="ă<>";window.a.href.includes("http") ? false : alert("ă")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="∾<>";window.a.href.includes("http") ? false : alert("∾")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="∿<>";window.a.href.includes("http") ? false : alert("∿")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="∾̳<>";window.a.href.includes("http") ? false : alert("∾̳")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="Â<>";window.a.href.includes("http") ? false : alert("Â")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="â<>";window.a.href.includes("http") ? false : alert("â")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="´<>";window.a.href.includes("http") ? false : alert("´")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="А<>";window.a.href.includes("http") ? false : alert("А")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="а<>";window.a.href.includes("http") ? false : alert("а")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="Æ<>";window.a.href.includes("http") ? false : alert("Æ")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="æ<>";window.a.href.includes("http") ? false : alert("æ")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="⁡<>";window.a.href.includes("http") ? false : alert("⁡")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="𝔄<>";window.a.href.includes("http") ? false : alert("𝔄")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="𝔞<>";window.a.href.includes("http") ? false : alert("𝔞")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="À<>";window.a.href.includes("http") ? false : alert("À")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="à<>";window.a.href.includes("http") ? false : alert("à")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="ℵ<>";window.a.href.includes("http") ? false : alert("ℵ")</script><base href="http://test.se"><a id="a"></a>0x0D
<script>window.a.href="ℵ<>";window.a.href.includes("http") ? false : alert("ℵ")</script>Fuzz results
Chrome 145.0.0.0 desktop macOS 10.15.7
Updated17 Feb 2026
Found 2124 results
Loading...
Chrome 144.0.0.0 desktop Windows NT 10.0older version
Updated17 Feb 2026
Found 2124 results
Loading...
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 1 result
Loading...
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated30 Jan 2026
Found 2124 results
Loading...