haozi / xss-demo

👮🏻‍♂️ XSS attack playground,there are answers in issues. XSS 攻防靶场,issues 有答案
https://xss.haozi.me
295 stars 58 forks source link

0x0B #6

Closed 9ak47er closed 5 years ago

9ak47er commented 6 years ago

image 大写也能执行

ba1ma0 commented 6 years ago

本地服务器放了一个1.js(js的内容是alert(1))但是好像弹不出来

haozi commented 5 years ago

本地是 http 环境吧,xss.haozi.me 是 https 的