Is escaping < and> sufficient to block XSS attacks?

后端 未结 4 1676
忘掉有多难
忘掉有多难 2021-02-05 12:46

I\'m sure that the answer to this question is No, but I can\'t seem to find a way that simply transforming < and > to < and <

4条回答
  •  南笙
    南笙 (楼主)
    2021-02-05 13:22

    Not all XSS attacks include < or > at all, depending on where the data is being inserted.

    https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet#Why_Can.27t_I_Just_HTML_Entity_Encode_Untrusted_Data.3F

提交回复
热议问题