Web Hack List

Collected research

One vector to rule them all

A single XSS payload built to execute wherever it lands: inside double or single quotes, inside an attribute, or in element content. It closes a long run of contexts (script, title, textarea, noscript, style, xmp, comments and CDATA) then offers many handlers at once - autofocus/onfocus, onerror, onclick, onmouseover, expression and background - each calling eval(name).

Record

Researcher
Gareth Heyes
Published by
thespanner.co.uk
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .