΢ÈíµÄAjaxÌí¼Ó²»ÉÏ - .NET¼¼Êõ / ASP.NET
<configSections>
<section name="rewriter" requirePermission="false" type="Intelligencia.UrlRewriter.Configuration.RewriterConfigurationSectionHandler, Intelligencia.UrlRewriter"/>
<sectionGroup name="system.web.extensions" type="System.Web.Configuration.SystemWebExtensionsSectionGroup, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
<sectionGroup name="scripting" type="System.Web.Configuration.ScriptingSectionGroup, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
<section name="scriptResourceHandler" type="System.Web.Configuration.ScriptingScriptResourceHandlerSection, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" requirePermission="false" allowDefinition="MachineToApplication"/>
<sectionGroup name="webServices" type="System.Web.Configuration.ScriptingWebServicesSectionGroup, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35">
<section name="jsonSerialization" type="System.Web.Configuration.ScriptingJsonSerializationSection, System.Web.Extensions, Version=1.0.61025.0, Culture=neutral, PublicKeyToken=31bf3856
Ïà¹ØÎÊ´ð£º
°´Å¥·ÅÔÚUpdatePanel1£¬Ïëͨ¹ýµã»÷µ÷ÓÃDictionaryTvAdd.aspxµ¯³öÒ»¸ö×Ó´°Ìå
ÓÃÏÂÃæµÄÓï¾äÌáʾÎÒȱÉÙ¶ÔÏó
protected void Button1_Click(object sender, EventArgs e)
{
ScriptManager.R ......
ÎÒÔÚÒ»¸öhtmlÖÐдÈçÏ´úÂ룺
JScript code:
<html>
<head>
<script type="text/javascript" charset="utf-8"
src="script/jquery-1.3.2.min ......
±¾ÈËÊDzËÄñÒ»¸ö£¬Æ½Ê±Òª×öÉúÒ⣬µ«ÊÇÕÒÁ˺ܶàÈË×öÍøÕ¾£¬¾ù±»ÆÁË¡£×öµÃ²»Èý²»ËÄ£¬ÏÖÔÚ¾öÐÄ×Ô¼ºÀ´×öÒ»¸ö£¬ÒÑѧϰASP.NETÏà¹ØµÄÍøÒ³ÖÆ×÷֪ʶ£¬ÓÐDW»ù´¡£¬¿ÉÒÔ˵ÊÇÄ¿Ç°Ö»ÓÐÀíÂÛ֪ʶ£¬µ«ÊÇÔÚʵ¼Ê¾ßÌå²Ù×÷µÄʱºò£¬×ÜÊÇÓöµ ......
´úÂëÖУ¬Èç¹û½«//alert(1)¡¡×¢ÊÍ´ò¿ª£¬ÄÇô¾Í¿ÉÒÔµ÷Óã¬Èç¹û×¢Ê͵ô¾ÍÎÞ·¨µ÷ÓÃ
»³ÒÉÊǵ¼JSÎļþ³öÎÊÌâÁË£¬ÒòΪд¹ýjspÒýÁ½¸öJSÎļþûÎÊÌ⣬
¶øJSPÒýÒ»¸öJSÎļþ£¬Õâ¸öJSÒý±ðÍâµÄJSÎļþ³öÏÖÏÂÃæÎÊÌ⣬ÉÏÍøÕÒÁË°ëÌìû½á ......