html() and the many jQuery functions which accept HTML strings as arguments are more prone to DOM-based XSS injection than innerHTML , as noticed by the OP.
確定! 回上一頁