Lab: Reflected XSS into HTML context with nothing encoded

Lab: Stored XSS into HTML context with nothing encoded

Lab: DOM XSS in document.write sink using source location.search

Lab: DOM XSS in innerHTML sink using source location.search

Lab: DOM XSS in jQuery anchor href attribute sink using location.search source

Lab: DOM XSS in jQuery selector sink using a hashchange event

Lab: Reflected XSS into attribute with angle brackets HTML-encoded

Lab: Stored XSS into anchor href attribute with double quotes HTML-encoded

Lab: Reflected XSS into a JavaScript string with angle brackets HTML encoded