XSS

Try XSS in every input field, host headers, url redirections, URI paramenters and file upload namefiles.

Actions: phising through iframe, cookie stealing, always try convert self to reflected.

Tools

Oneliners

XSS recopilation

Basics

By tag

Blind

Bypasses

Encoded

Polyglots

XSS in files

DOM XSS

XSS to CSRF

AngularJS Sandbox

XSS in JS

XSS Waf Bypasses

XSS Mindmap

Last updated

Was this helpful?