divclass="comment""你的评论在这里"onmouseover="...
imgsrc=xonerror=alert(1)...
scriptalert(1)/script...
<pre style="font-family: 'Lucida Console'; font-size: 0.9em; background-color: rgb(255, 255, 204);">Line 44: if (model != null) Line 45: { <span style="color:red;">Line 46: return "../" + Common.ApplicationMethods.GetClientHead(model.Access, size); </span>Line 47: } Line 48: return "";</pre>
<p>本地测试没问题,你后台登陆的时候输入的用户名不对吧?应该是多了个空格啥的。</p>