Bellow代码容易受到XSS攻击。我已经核实过了。我想把它修好。我该怎么做呢?代码是用经典的asp编写的。
Dim strGo : strGo = Request.QueryString.Item("go");
Response.Write "document.location.href = 'browserCompatibilities.asp?go=" & strGo;
发布于 2021-09-14 15:02:43
您必须对查询字符串参数执行encode
操作:
Response.Write "document.location.href = 'browserCompatibilities.asp?go=" &
Server.HTMLEncode(strGo)
https://stackoverflow.com/questions/69178541
复制相似问题