首页 诗词 字典 板报 句子 名言 友答 励志 学校 网站地图
当前位置: 首页 > 教程频道 > 网站开发 > CSS >

轮换HTML Code

2012-09-18 
替换HTMLCodeJSP语言可以通过替换输出数据的特殊字符【& ” ’ ( )%+-】为其他表示形式后再输出给客户端,

替换HTML Code
JSP语言可以通过替换输出数据的特殊字符【& < > ” ’ ( )%+-】为其他表示形式后再输出给客户端,例如:

<%String OutStr = "<script>alert('XSS')</script>";OutStr = OutStr.replaceAll("&","&amp;");OutStr = OutStr.replaceAll("<","&lt;");OutStr = OutStr.replaceAll(">","&gt;");OutStr = OutStr.replaceAll(""","&quot;");OutStr = OutStr.replaceAll("\'","&#39;");OutStr = OutStr.replaceAll("\\(","&#40;");OutStr = OutStr.replaceAll("\\)","&#41;");OutStr = OutStr.replaceAll("%","&#37;");OutStr = OutStr.replaceAll("\\+","&#43;");OutStr = OutStr.replaceAll("-","&#45;");out.println(OutStr);%>

热点排行