divclass="comment""你的评论在这里"onmouseover="...
imgsrc=xonerror=alert(1)...
scriptalert(1)/script...
配置文件中修改: <connectionStrings> <remove name="LocalSqlServer" /> <add connectionString="Data Source=.\sql2008;AttachDBFilename=|DataDirectory|aspnetdb.mdf;User ID=sa;pwd=sa" name="LocalSqlServer" providerName="System.Data.SqlClient" /> </connectionStrings>修改了<connectionStrings>中德数据库连接为你电脑上的就可以了