j" is valid, regardless of the encoding type because the browser knows it in context of a SCRIPT tag. <SCRIPT SRC=//xss.rocks/.j>. Half Open HTML/JavaScript XSS ...
確定! 回上一頁