1: <%@page contentType="text/html" pageEncoding="UTF-8"%> 2: 3: 4: 5: 6: 7:

XSS Sample

8: <% 9: 10: String name = request.getParameter("name"); 11: 12: 13: if ( name != null ) { 14: name = name.replaceAll("<","<"); 15: name = name.replaceAll(">",">"); 16: } else { 17: return; 18: } 19: %> 20: 21:

NAME:<%=name%>

22: 23: