ASP³ÌÐòµ÷ÊÔ
ÊÖÍ·Ö»ÓÐDW
ÐÞ¸ÄASP³ÌÐò£¬²»ÖªµÀÔõôµ÷ÊÔ¡£
¾ÍÏñJSÖеÄalert£¨£©ÕâÑùµÄµ÷ÊԾͿÉÒÔ¡£
ÔõôÔÚASP³ÌÐòÖÐÊä³ö¹ý³Ì±äÁ¿µÄÖµ£¿
û·¢Ïֵĺõķ½·¨£¬²»¹ýÊä³öjavascriptÒ²Ðа¡
VBScript code:
response.write("<script>alert('alert word')</script>")
Ò»°ã¶¼ÊÇÀàËÆ2Â¥µÄ·½Ê½À´ÊµÏÖ£¬²»¹ý¿ÉÒÔ×öÒ»¸öº¯Êý¿â¡£×öÀàËÆµÄº¯Êý
sub msg(s_str)
response.write(" <script>alert('"&s_str&"') </script>")
end sub
Ïà¹ØÎÊ´ð£º
<%if request.QueryString("start") <>"" then%>
<%if cint(start)>0 then%>
<a href="search.asp?q= <%=q%>&start= <%if request.Query ......
Îļþ£ºfolder.inc
HTML code:
<%
Dim folderini,pos,pageName
fPath = Request.ServerVariables("PATH_TRANSLATED")
pos = instrRev(fPath,"\")
folderini = Left(fPath,pos)+&qu ......
ÎÒ°ïѧУ×öÁËÒ»¸öÕ¾£®
ÔÚÐ£Ô°ÍøµÄÇé¿öÏ£¬Äܹ»µÇ½³É¹¦£¬ºǫ́ÕʺŶ¼ÄÜͨ¹ý£¬½øÈëºǫ́
µ«ÊÇÔÚÍâÍø£Á£ÄµÄÇé¿öÏ£¬Äܹ»µÇ½ºǫ́µÄÒ³Ãæ£¬Ò³ÃæÊÇ£Á£Ó£ÐÎļþ£®
µ«ÊÇÊäÈëÕʺźÍÃÜÂëµÄʱºò£¬ÍøÒ³ÔËÐкܾö¼ ......
ÔÚÒ»¸ö·¢±íÎÄÕµÄÒ³Ãæ£¬Èç¹ûÖÐ;¹Ø±ÕÒ³Ãæ£¬ÕâÌáʾÊÇ·ñ·ÅÆú±à¼£¬
Èç¹ûµã»÷·ÅÆú£¬ÔòתÏòÌîд·ÅÆúÔÒòµÄ½çÃæ£¬
Èç¹ûµã²»·ÅÆú£¬ÕâÍ£ÁôÔÚÔÒ³Ãæ£¬
Èç¹ûÊǵã»÷Ò³ÃæµÄ³¬¼¶Á´½Ó£¬Ôò´¥·¢Ê¼þʧЧ
ÈçºÎ±àд´ú ......
Ìý˵ÓÃasp×öµÄÍøÒ³,Ò»ÕÅͼƬ¾ÍÊÇÒ»¸öiisÁ¬½ÓÊý,¸÷λ¸ç¸ç,½ã½ãÊDz»Êǰ¡?ÎÒÓÃasp×öµÄÍøÒ³,ÿҳ¶¼ÓÐ30ÕÅͼƬ,ÿҳ¾ÍÕ¼30¸öÁ¬½ÓÊý¶ÔÂð?ÕâÑùµÄÍøÒ³ÎÒ×öÁ˼¸Ê®Ò³,ÍøÕ¾»¹ÄÜ´ò¿ªÂð?Ï£Íû¸ßÊֻشðÎÒ?
ʲôÒâ˼¡£¡£¡£
ÄãÌýË ......