日期:2014-05-17 浏览次数:20691 次
<% String OutStr = "<script>alert('XSS')</script>"; OutStr = OutStr.replaceAll("&","&"); OutStr = OutStr.replaceAll("<","<"); OutStr = OutStr.replaceAll(">",">"); OutStr = OutStr.replaceAll("\"","""); OutStr = OutStr.replaceAll("\'","'"); OutStr = OutStr.replaceAll("\\(","("); OutStr = OutStr.replaceAll("\\)",")"); OutStr = OutStr.replaceAll("%","%"); OutStr = OutStr.replaceAll("\\+","+"); OutStr = OutStr.replaceAll("-","-"); out.println(OutStr); %>