XSSxss
http://netsecurity.51cto.com/art/201408/448305_all.htmspa
檢驗: 輸入<script>alert('xss')</script>,檢查xxs存在性htm
預防: 對全部請求加上filter過濾ip