摘要: 1.反射型XSS: <?php $input = $_GET["param"];echo "<div>".$input."</div>"; ?> http://localhost//XSS/new%201.php?param=这是一个测试! http://localhost//XSS/new%201 阅读全文