Home  >  Article  >  Web Front-end  >  Example interpretation of methods to execute arbitrary html code in javascript_javascript skills

Example interpretation of methods to execute arbitrary html code in javascript_javascript skills

WBOY
WBOYOriginal
2016-05-16 17:07:09997browse

I accidentally discovered a situation in the code today where the javascript eval() function cannot execute the html code, such as:

Copy the code The code is as follows :

<script>eval('<li>hehe</li>')</script>

The code will not be executed, but Change it to the following and you can execute it:
Copy the code The code is as follows:

<script> eval('</script>
  • hehe
  • <script>')</script>
    Statement:
    The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn