jsp 之反射型 xss 示例

发布时间 2023-09-27 10:48:08作者: zhuangrunwei
jsp代码如下:
<%@ page contentType="text/html; charset=UTF-8" pageEncoding="UTF-8" %>
<!DOCTYPE html>
<html>
<body>
<form action="" method="get">
    姓名:<input name="name" type="text">
    密码:<input name="passwd" type="password">
    <button type="submit">提交</button>
</form>

<%
    String name = request.getParameter("name");
    String passwd = request.getParameter("passwd");
    if (name != null && name != "") {
        out.write(name);
        out.write("<br>");
        out.write(passwd);
    }
%>
</body>
</html>