A. xml实体注入 B. 服务器端请求伪造 C. 跨站请求伪造 D. 跨站脚本攻击
A. <script>alert(/xss/)</script> B. <a>alert(/xss/)</a> C. <a href="javascript:alert('xss')">2</a> D. <script>eval(String.fromCharCode(97, 108, 101, 114, 116, 40, 49, 50, 51, 41))</script>
A. 对 B. 错