NodeJS - XSS-Attribute

参考:https://owasp-skf.gitbook.io/asvs-write-ups/cross-site-scripting-attribute-xss-attribute/kbid-3-xss-attribute

f12看看

修改color的值,英文句子就会改变颜色,这里也就是输入框里输入的字符串,尝试注入

<span style="color:red " onmouseover="alert(1337)" ;'> Let me be a color!</span> 双引号闭合了前面的color,同时添加了onmouseover属性,成功弹窗

posted @ 2023-01-24 19:41  smile_2233  阅读(25)  评论(0编辑  收藏  举报