Havij Persistent XSS (<=v1.10)
Havij does not do any filtration in Target bar so XSS codes can be executed. However, you need to find a site that is vulnerable to XSS and SQL Injection. The site cannot be vulnerable to just XSS only as Havij will stop working as it cannot inject it. Functions Affected: Save in Info, Save Tables in Tables, Save Data in Tables. Eventhough I said you need to find a site that is vulnerable to XSS and SQL Injection, There is also an exception to this. Instead, you can find a site vulnerable to SQL Injection and use SiXSS to generate your desired XSS code. You can also put the XSS code after the Vulnerable Parameter. Of course, before that you would need to find the column count and string column and replace the String column with the XSS code.