[查看演示] 源码如下 ---------------------------------------------------------- <html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
<title>Escaped JavaScript quotes in HTML-51windows.Net-www.51windows.Net</title>
</head>
<body>
<A HREF="javascript:alert('xxx\'xxx');">Test 2.1</A><BR>
<A HREF='javascript:alert("xxx\"xxx");'>Test 2.2</A><BR>
<A HREF="javascript:alert('xxx"xxx');">Test 2.3</A><BR>
<A HREF='javascript:alert("xxx'xxx");'>Test 2.4</A><BR>
<A HREF="javascript:alert('xxx\047xxx');">Test 2.5</A><BR>
<A HREF="javascript:alert('xxx\x27xxx');">Test 2.6</A><BR>
<A HREF="javascript:alert('xxx\u0027xxx');">Test 2.7</A><BR>
<A HREF="javascript:alert('xxx\042xxx');">Test 2.8</A><BR>
<A HREF="javascript:alert('xxx\x22xxx');">Test 2.9</A><BR>
<A HREF="javascript:alert('xxx\u0022xxx');">Test 2.10</A><BR>
</body>
</html>
<div style="position: absolute; top: 10; right: 10; width: 148; height: 18;cursor:hand">
<input type="button" name="Button" value="查看源代码" onClick= 'window.location = "view-source:" + window.location.href'></div> |