Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS的htmlspecialchars绕过,双引号问题 #16

Open
ningningjia opened this issue Jan 30, 2022 · 0 comments
Open

XSS的htmlspecialchars绕过,双引号问题 #16

ningningjia opened this issue Jan 30, 2022 · 0 comments

Comments

@ningningjia
Copy link

ningningjia commented Jan 30, 2022

我在写这个的时候,看到了默认只对双引号转译。但当我实际提交查看网页源码时,发现<a herf="我输入的内容",即herf变成了双引号包裹,而输入中无法正常使用“,导致此题我解不出来。去网上看了一些其他帖子,他们的herf都是单引号包裹的。我特地看了一一下php代码文件,里面的确写的是单引号包裹,我很疑问这是为什么到网页上就变成双引号了。我使用的是XAMPP,PHP7。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant