Google Dork list for XSS

Abhishek Kafle
2 min readFeb 26, 2023
Cross Site Scripting Dorks

Cross-Site Scripting (XSS) is a common vulnerability found in web applications that allows an attacker to inject malicious code into a web page viewed by other users. As a security researcher or ethical hacker, Google Dorks are an effective way to identify websites that may be vulnerable to XSS attacks. Here are some Google Dorks that can help you find XSS vulnerabilities:

  1. inurl:index.php?id=
  2. inurl:product.php?id=
  3. inurl:category.php?id=
  4. inurl:article.php?id=
  5. inurl:gallery.php?id=
  6. inurl:page.php?id=
  7. inurl:show.php?id=
  8. inurl:detail.php?id=
  9. inurl:view.php?id=
  10. inurl:newsitem.php?num=
  11. inurl:readnews.php?id=
  12. inurl:topic.php?ID=
  13. inurl:forum.php?topic=
  14. inurl:viewforum.php?id=
  15. inurl:profile.php?id=
  16. inurl:showthread.php?t=
  17. inurl:member.php?action=profile&id=
  18. inurl:productlist.php?id=
  19. inurl:shop_category.php?id=
  20. inurl:catalog.php?cat=

These Google Dorks are used by ethical hackers to identify websites that may be vulnerable to XSS attacks. By searching for websites that have URLs containing these parameters, hackers can try to inject malicious scripts into those pages and see if they are executed by the website. If the website is vulnerable, the scripts will execute, potentially allowing the hacker to gain access to sensitive information or take control of the website.

It’s important to note that these Google Dorks are just one tool in a hacker’s toolkit. Ethical hackers and security researchers use them to identify vulnerabilities, but they also use other techniques such as manual testing and automated tools to find and exploit vulnerabilities. If you are a website owner or developer, it’s important to keep your website up-to-date and secure to prevent XSS and other types of attacks.

--

--

Abhishek Kafle

Lover of Bash |Alpha-Geek|Infosec Poet|Learner "Wisdom begins in wonder"