xss_reflected_test
Test for reflected XSS vulnerabilities by sending 10 payloads to a URL parameter and checking if they appear unescaped in the response. Returns detailed results including vulnerable count.
Instructions
Test multiple reflected XSS vectors against a parameter. Sends 10 payloads (script tags, event handlers, SVG, attribute injection, case variation, template literals) and checks if they appear unescaped in the response. Returns results array with reflected/encoded/status per payload, and vulnerable_count. Side effects: Read-only GET requests. Sends 10 requests.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | URL with reflectable parameter, e.g. https://target/search?q=test | |
| parameter | Yes | Parameter name that reflects input, e.g. 'q' |