CheckXSS – Detect XSS vulnerability in Web Applications
data:image/s3,"s3://crabby-images/44713/44713cfffdeb099a28c698de77d7f3fe891058a0" alt="CheckXSS - Detect XSS vulnerability in Web Applications 1 CheckXSS 1"
Detect XSS vulnerability in Web Applications
Screenshots
data:image/s3,"s3://crabby-images/2be27/2be27294e15017c0e7364e740f7c349109e34828" alt="CheckXSS - Detect XSS vulnerability in Web Applications 2 CheckXSS 8"
Easy Installation
As simple as below, Just one line of code:
curl -L -s https://raw.githubusercontent.com/Jewel591/CheckXSS/master/docs/install.sh|bash
Usage Instructionspython3.6 checkxss.py -h
data:image/s3,"s3://crabby-images/cafb9/cafb93b0aba161900395abf6e72f82ea001e449e" alt="CheckXSS - Detect XSS vulnerability in Web Applications 3 CheckXSS 9"
Support POST and GET request methods, support parameter injection detection in cookie, referer, useragent fields For example, test the returnUrl parameter in POST data:python3.6 checkxss.py -u "https://example.com/login.do" --data="returnUrl=utest" -p returnUrl
data:image/s3,"s3://crabby-images/2bf61/2bf610d54fb1f34c82f0a1b35b3fc9ffb46908ba" alt="CheckXSS - Detect XSS vulnerability in Web Applications 4 CheckXSS 10"
Features
- Support url encoding bypass
- Support unicode encoding of HTML tag attribute value to bypass
- Support HTML encoding to bypass the HTML tag attribute value
- Support for flexible replacement of () ‘”to bypass
- Case bypass
Contributing
Contributions, issues and feature requests are welcome!
Feel to check issues page
Maintainers
@Jewel591
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.