Entities allowed between slashes using XSS type

Chrome logo 4
Firefox logo 4
Safari logo 4

This is an example how you can use the XSS type to fuzz URLs. It uses a base tag to get round the sandboxed iframe problems.

Created by: hackvertor

Created on: Thursday, January 16, 2025 at 6:50:23 PM

Updated on: Thursday, January 16, 2025 at 6:50:23 PM

Vector type: XSS

Vector charset: UTF-8

Code used before fuzz:
<script>window.onerror=x=>true;</script>
<base href="https://example.com" />
Template used:
<a href="/$[data1]/example2.com" id=x></a>
Code used after fuzz:
x.host === "example2.com" && log('$[data1]')
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...

Sample payloads

<a href="/&bsol;/example2.com" id=x></a>
<a href="/&NewLine;/example2.com" id=x></a>
<a href="/&sol;/example2.com" id=x></a>
<a href="/&Tab;/example2.com" id=x></a>

Fuzz results

Chrome logo
Chrome 132.0.0.0 desktop macOS 10.15.7

Updated

Thu Jan 16 2025
Found 4 results
Loading...
Firefox logo
Firefox 134.0 desktop macOS 10.15

Updated

Thu Jan 16 2025
Found 4 results
Loading...
Safari logo
Safari 18.2 mobile iOS 18.2.1

Updated

Thu Jan 16 2025
Found 4 results
Loading...