# Cross-site scripting Lab21 本題是 反射型 DOM XSS 發生在 JavaScript 的 Template Literal `(${...})` 中,而系統對輸入進行了某些過濾與轉換(像是 `<` `>` `'` `"` `\` `'` 全部都會被轉義成 Unicode 或 HTML entities),但 `${...}` 語法本身沒被過濾。 一樣先進入網站。  由題目敘述我們可以先試試看用 `${...}` 是否可以直接執行。 ``` ${alert(1)} ```  ---
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up