JavascriptÔÚÒ³Ãæ¼ÓÔØÊ±µÄÖ´ÐÐ˳Ðò
Ò»¡¢ÔÚHTMLÖÐǶÈëJavasriptµÄ·½·¨
Ö±½ÓÔÚJavascript´úÂë·ÅÔÚ±ê¼Ç¶Ô<script>ºÍ</script>Ö®¼ä
ÓÉ<script />±ê¼ÇµÄsrcÊôÐÔÖÆ¶¨ÍⲿµÄjsÎļþ
·ÅÔÚʼþ´¦Àí³ÌÐòÖУ¬±ÈÈ磺<p onclick="alert('ÎÒÊÇÓÉonclickʼþÖ´ÐеÄJavascript')">µã»÷ÎÒ</p>
×÷ΪURLµÄÖ÷Ì壬Õâ¸öURLʹÓÃÌØÊâµÄJavascript£ºÐÒ飬±ÈÈ磺<a href="javascript:alert('ÎÒÊÇÓÉjavascript:ÐÒéÖ´ÐеÄjavascript')">µã»÷ÎÒ</a>
ÀûÓÃjavascript±¾ÉíµÄdocument.write()·½·¨Ð´ÈëеÄjavascript´úÂë
ÀûÓÃAjaxÒì²½»ñÈ¡javascript´úÂ룬ȻºóÖ´ÐÐ
µÚ3Öֺ͵Ú4ÖÖ·½·¨Ð´ÈëµÄJavascriptÐèÒª´¥·¢²ÅÄÜÖ´ÐУ¬ËùÒÔ³ý·ÇÌØ±ðÉèÖ㬷ñÔòÒ³Ãæ¼ÓÔØÊ±²»»áÖ´ÐС£
¶þ¡¢JavascriptÔÚÒ³ÃæµÄÖ´ÐÐ˳Ðò
Ò³ÃæÉϵÄJavascript´úÂëÊÇHTMLÎĵµµÄÒ»²¿·Ö£¬ËùÒÔJavascriptÔÚÒ³Ãæ×°ÔØÊ±Ö´ÐеÄ˳Ðò¾ÍÊÇÆäÒýÈë±ê¼Ç<script />µÄ³öÏÖ˳Ðò£¬ <script />±ê¼ÇÀïÃæµÄ»òÕßͨ¹ýsrcÒýÈëµÄÍⲿJS£¬¶¼Êǰ´ÕÕÆäÓï¾ä³öÏÖµÄ˳ÐòÖ´ÐУ¬¶øÇÒÖ´Ðйý³ÌÊÇÎĵµ×°ÔصÄÒ»²¿·Ö¡£
ÿ¸ö½Å±¾¶¨ÒåµÄÈ«¾Ö±äÁ¿ºÍº¯Êý£¬¶¼¿ÉÒÔ±»ºóÃæÖ´ÐеĽű¾Ëùµ÷Óá£
±äÁ¿µÄµ÷Ó㬱ØÐëÊÇÇ°ÃæÒѾÉùÃ÷£¬·ñÔò»ñÈ¡µÄ±äÁ¿ÖµÊÇundefined¡£
<script type="text/javscrpt">//<![CDATA[
alert(tmp); //Êä³ö undefined
var tmp = 1;
alert(tmp); //Êä³ö 1
//]]></script>
ͬһ¶Î½Å±¾£¬º¯Êý¶¨Òå¿ÉÒÔ³öÏÖÔÚº¯Êýµ÷ÓõĺóÃæ£¬µ«ÊÇÈç¹ûÊÇ·Ö±ðÔÚÁ½¶Î´úÂ룬ÇÒº¯Êýµ÷ÓÃÔÚµÚÒ»¶Î´úÂëÖУ¬Ôò»á±¨º¯Êý䶨Òå´íÎó¡£
<script type="text/javscrpt">//<![CDATA[
aa(); //ä¯ÀÀÆ÷±¨´í
//]]></script>
<script type="text/javscrpt">//<![CDATA[
aa(); //Êä³ö 1
function aa(){alert(1);}
//]]></script>
document.write()»á°ÑÊä³öдÈëµ½½Å±¾ÎĵµËùÔÚµÄλÖã¬ä¯ÀÀÆ÷½âÎöÍêdocumemt.write()ËùÔÚÎĵµÄÚÈݺ󣬼ÌÐø½âÎödocument.write()Êä³öµÄÄÚÈÝ£¬È»ºóÔÚ¼ÌÐø½âÎöHTMLÎĵµ¡£
<script type="text/javascript">//<![CDATA[
document.write('<script type="text/javascript" src="test.js"><\\/script>');
document.write('<script type="text/javascript">');
document.write('alert(2);')
document.write('alert("ÎÒÊÇ" + tmpStr);');
document.write('<\\/script>');
//]]><
Ïà¹ØÎĵµ£º
±íµ¥µÄ¿Í»§¶ËjavascriptÑéÖ¤Óи÷ÖÖ¸÷ÑùµÄд·¨£¬µÇ¼ΪformµÄonsubmitʼþ»òsubmit°´Å¤Ð´Ò»¸öº¯Êý¡£¶ÔÓÚС±íµ¥£¨Ö»ÓÐÒ»Á½¸ö±íµ¥ÓòµÄ±íµ¥£©¾Í²»±ØÔÙרÃÅÔÙÓÃjavascriptдһ¸öÑéÖ¤º¯ÊýÁË£¬Ö»ÐèÒªÔÚformµÄonsubmitʼþÀï¼ÓÉÏ£º
onsubmit=”return domainname.value==”?(alert(’ÇëÊäÈëËÑË÷ÄÚÈÝ’),false ......
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<title>vForm±íµ¥ÑéÖ¤³Ì ......
Æ¥ÅäÖÐÎÄ×Ö·ûµÄÕýÔò±í´ïʽ£º [u4e00-u9fa5]
ÆÀ×¢£ºÆ¥ÅäÖÐÎÄ»¹ÕæÊǸöÍ·ÌÛµÄÊ£¬ÓÐÁËÕâ¸ö±í´ïʽ¾ÍºÃ°ìÁË
Æ¥ÅäË«×Ö½Ú×Ö·û(°üÀ¨ºº×ÖÔÚÄÚ)£º[^x00-xff]
ÆÀ×¢£º¿ÉÒÔÓÃÀ´¼ÆËã×Ö·û´®µÄ³¤¶È£¨Ò»¸öË«×Ö½Ú×Ö·û³¤¶È¼Æ2£¬ASCII×Ö·û¼Æ1£©
Æ¥Åä¿Õ°×ÐеÄÕýÔò±í´ïʽ£ºns*r
ÆÀ×¢£º¿ÉÒÔÓÃÀ´É¾³ý¿Õ°×ÐÐ
Æ¥ÅäHTML±ê¼ÇµÄÕýÔò±í´ïʽ£º< (S ......
¶þÊ®¡¢Bookmarklet
1¡¢Ê²Ã´ÊÇBookmarklet£¿£¨What's a Bookmarklet?£©
Q£ºÊ²Ã´ÊÇBookmarklet£¿
A£ºBookmarkletÊÇÕû¸ö¶¼±»°üº¬ÔÚ³¬Á´½ÓURLÖеÄһС¶ÎJavaScript³ÌÐò¡££¨JavaScript URL¾ÍÊÇÕâ¸öÑù×Ó£º<a href="javascript:the code goes here">¡££©¶àÊýä¯ÀÀÆ÷ÔÊÐíÓû§Ìí¼ÓÕâЩJavaScript URLÊéÇ©£¬¾ÍÏñÌí¼ÓÆäËû³¬Á´½ ......