mirror of
https://github.com/minimaxir/big-list-of-naughty-strings.git
synced 2025-09-24 21:01:32 +02:00
Add backtick special character list because IE7 allows it as attribute quotes. Add basic attribute escapes to XSS list.
This commit is contained in:
6
blns.txt
6
blns.txt
@@ -40,7 +40,7 @@ Infinity
|
||||
|
||||
,./;'[]\-=
|
||||
<>?:"{}|_+
|
||||
!@#$%^&*()
|
||||
!@#$%^&*()`
|
||||
|
||||
# Unicode Symbols
|
||||
#
|
||||
@@ -177,6 +177,10 @@ Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮
|
||||
<script>alert('hi')</script>
|
||||
<img src=x onerror=alert('hi') />
|
||||
<svg><script>0<1>alert('XSS')</script>
|
||||
"><script>alert(document.title)</script>
|
||||
><script>alert(document.title)</script>
|
||||
'><script>alert(document.title)</script>
|
||||
"><script>alert(document.title)</script>
|
||||
|
||||
# SQL Injection
|
||||
#
|
||||
|
Reference in New Issue
Block a user