DOM-Based Cross Site Scripting
Check List
Methodology
Black Box
1
2
3
4
5
6
7
8
1
2
3
4
5
6
7
https://example.org/search?q=@<script>prompt(1337)</script>gmail.comSPA Sites
1
2
3
4
5
https://target.com/search?q=<img src=x onerror=alert(1)>6
#<svg onload=alert(1)>7
White Box
Cheat Sheet
Last updated