Cross Site Scripting (XSS)

  1. Payload Construction and Techniques
    1. Basic Payload Structures
      1. Script Tag Injection
        1. Inline JavaScript
          1. External Script Loading
            1. Script Attribute Manipulation
            2. Event Handler Exploitation
              1. Mouse Events
                1. Keyboard Events
                  1. Load Events
                    1. Error Events
                      1. Focus Events
                      2. Image-Based Payloads
                        1. Error Event Triggers
                          1. SVG Script Injection
                            1. Data URI Schemes
                          2. Advanced Payload Techniques
                            1. HTML Attribute Context
                              1. href Attribute Injection
                                1. src Attribute Manipulation
                                  1. style Attribute Exploitation
                                  2. JavaScript Context Injection
                                    1. String Escape Techniques
                                      1. Variable Assignment Exploitation
                                        1. Function Parameter Injection
                                        2. CSS Context Exploitation
                                          1. Expression Injection
                                            1. Import Statement Manipulation
                                              1. URL Function Exploitation
                                              2. Iframe-Based Attacks
                                                1. Nested Frame Injection
                                                  1. Sandbox Bypass Attempts
                                                2. Payload Obfuscation
                                                  1. Encoding Techniques
                                                    1. HTML Entity Encoding
                                                      1. URL Encoding Methods
                                                        1. Unicode Normalization
                                                          1. Base64 Encoding
                                                          2. String Manipulation
                                                            1. Concatenation Techniques
                                                              1. Character Code Conversion
                                                                1. Regular Expression Bypass
                                                                2. Filter Evasion
                                                                  1. Keyword Fragmentation
                                                                    1. Case Variation Exploitation
                                                                      1. Whitespace Manipulation
                                                                        1. Comment Insertion