duanbigan7765 2016-05-12 13:21
浏览 34
已采纳

XSS没有在表单上工作

Here is a simple form that I want to try and attack with XSS. I am using Chrome.

  <?php
    echo  $_GET['comment'];
  ?>
  <script>alert('from HTML')</script>

  <form method="GET" action="">
    Name: 
    <input type="text" name="name" />
    <br/><br/>
    Comment:
    <input type="text" name="comment" />
    <br/><br/>
    <input type="submit" value="Submit" />
  </form>

So I entered into the comment text-box the following: <script>alert('hi')</script>. However, it's not working. The only alert box that pops up is from HTML which I have written directly into the code. When looking at the page source the following is written:

<script>alert('hi')</script>
<script>alert('from HTML')</script>

Why is it not executing the first alert?

  • 写回答

1条回答 默认 最新

  • doujionggan9570 2016-05-12 14:03
    关注

    Check the console tab in the developer tools of your browser. My guess is that your browser has XSS protection enabled.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥20 有关区间dp的问题求解
  • ¥15 多电路系统共用电源的串扰问题
  • ¥15 slam rangenet++配置
  • ¥15 有没有研究水声通信方面的帮我改俩matlab代码
  • ¥15 对于相关问题的求解与代码
  • ¥15 ubuntu子系统密码忘记
  • ¥15 信号傅里叶变换在matlab上遇到的小问题请求帮助
  • ¥15 保护模式-系统加载-段寄存器
  • ¥15 电脑桌面设定一个区域禁止鼠标操作
  • ¥15 求NPF226060磁芯的详细资料