DVWA - XSS (Reflected) (low, medium, high)

low

无验证,直接注入

<script>alert(document.cookie)script>

medium

查看源码发现过滤了标签

$name = str_replace( '
                    
                    

你可能感兴趣的:(CTF)