读书人

跨站脚本破绽(XSS)示例

发布时间: 2012-12-30 10:43:15 作者: rapoo

跨站脚本漏洞(XSS)示例
index.jsp

<%@ page language="java" contentType="text/html; charset=UTF-8" pageEncoding="UTF-8"%><!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><title>Insert title here</title></head><body><!-- http://sjy:8008/demo/index.jsp?meg=<script>alert('XSS%20attack')</script> --><%String message = request.getParameter("meg"); %><%=message %><form action="" method="post"><input  type="hidden" value="<%=message%>"></form></body></html>


上面代码容易被XSS攻击,做个记录!

读书人网 >互联网

热点推荐