burpsuite靶场----XSS----存储型XSS1
burpsuite靶场----XSS----存储型XSS1
靶场地址
https://portswigger.net/web-security/cross-site-scripting/stored/lab-html-context-nothing-encoded
XSS字典
链接:https://pan.baidu.com/s/1XAJbEc4o824zAAmvV85TOA
提取码:1234
正式开始
找到评论区的地方
插入payload