in `/admin/setup.php` we should input sitename、username、email to setup website. but if any error in the installation, these three parameters will be returned back to the page without any filter.
we can use double quote to escape and execute any javascript script.
暂无评论