•  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
r16
r1

(새 문서)
1{{{#!html
r4
2<a href="javascript:alert('XSS')">XSS</a>
r5
3<script>
r6
4 alert('hello');
r5
5</script>
r7
6<meta http-equiv="refresh" content="0; url=https://namu.wiki"></meta>
7<meta http-equiv="refresh" content="0; url=https://namu.wiki"></meta>
r8
8<img src="#" onerror="alert('XSS')">
r9
9<ruby oncopy="alert('XSS')">XSS</ruby>
r10
10<a href="&#x6A;&#x61;&#x76;&#x61;&#x73;&#xA;&#x63;&#x72;&#x69;&#x70;&#x74;&#xA;&#x3A;&#xA;&#x61;&#x6C;&#x65;&#x72;&#x74;&#xA;&#x28;&#x27;&#x58;&#x53;&#x53;&#x27;&#x29;">XSS</a>
r1

(새 문서)
11}}}
r5
12막힌거 확인
r8
13
r11
14{{{#!syntax javascript
15router.get(/^\/contribution\/(ip|author)\/(.+)\/edit_request$/, async function EditRequestList(req, res) {
16 const ismember = req.params[0];
17 const username = req.params[1];
18 var moredata = [];
19
20var data = await curs.execute("select flags, title, namespace, rev, time, changes, log, iserq, erqnum, advance, ismember, username, loghider from history \
21 where cast(time as integer) >= ? and ismember = ? " + (username.replace(/\s/g, '') ? "and lower(username) = ?" : "and (lower(username) like '%' || ?)") + " order by cast(time as integer) desc", [
22 Number(getTime()) - 2592000000, ismember, username.toLowerCase()
23 ]);
24}}}
25
r12
26{{{#!html
27<h1>와우 친구들! 빡빡이 아저씨야</h1>
28}}}
29
r11
30렌더링 의외로 잘 되는듯
31