标题的<script>可执行!
无害演示链接: http://tieba.baidu.com/f?kz=1121728662
无害演示链接: http://tieba.baidu.com/f?kz=1121728662
1
apple Jun 26, 2011
还真是的。
|
2
ihacku Jun 26, 2011
“</script>just for fun<script>alert(“hacked by xxx”)</script>
|