let userInput = filterHTML('\<script\>alert("abc")\</script\>'); // 恶意代码
function filterHTML(string) {
let s = '';
for (let i = 0; i < string.length; i++) {
let arg = string[i];
s += arg.replace(/&/g, "&")
.replace(/</g, "<")
.replace(/>/g, ">");
}
return s;
}
document.write(userInput);
187

被折叠的 条评论
为什么被折叠?



