XSS Test1

(1) srcdoc属性

Code

<iframe srcdoc="<script>console.log('XSS');</script>"></iframe>

Demo

参考

(2) "data" URL scheme

Code

<iframe src="data:text/html;base64,PHNjcmlwdD5jb25zb2xlLmxvZygnWFNTJyk7PC9zY3JpcHQ+">

Demo

参考

(3) onmousemove 属性など

(3-1)

Code

<b onmousemove="console.log('XSS')">XSS!</b>

Demo

XSS!

(3-2) エスケープを利用する

Code

<b onmousemove="console.log('XSS')">XSS!</b>

Demo

XSS!

参考