沉铝汤的破站

IS LIFE ALWAYS THIS HARD, OR IS IT JUST WHEN YOU'RE A KID

xss

htmlspecialchars绕过

  1. 默认设置时不过滤单引号

    <?php echo "<input name=biubiu value='".htmlspecialchars($str)."'>";?>

    绕过: ' onclick='alert('xss')