???????????????

???????????????????????????????

?????? ????????????

?????????????????XSS????????У????????????????ó?????????????????????????????ó?????У???????????????????????2??????????????????XSS???????????????????????????磬???????????????cookie???????????????????????????????????????£?Input -> Output == cross-site scripting??

?????????? ?????????????

?????????? ???????洢????

?????????? ??????DOM????

?????????? FLASH???????

?????? SQL???

????SQL????????????п?????????????ó????У??????????????????????????????SQL??????????ó????????????????????????????????????SQL????????????????ó??????SQL?????????????????????????????δ????????????????????е????????????????????????????????????????SQL???????????£?Input -> Query SQL == SQL injection

????SQL????????????????

?????????? Oracle????

?????????? MySQL????

?????????? SQL Server????

?????????? MS ACCESS????

?????????? PostgreSQL????

?????? LDAP???

????LDAP????????????SQL???????????????????????????SQL???????LDAPЭ?飬????????????LDAP??????????????SQL????????LDAP???????????£?

????Input -> Query LDAP == LDAP injection

?????? ORM???

????ORM???????????????SQL?????????????????£????????SQL?????ORM???????????????????????????????????????????????SQL????????????????????д??????????????ORM??????????

?????? XML???

????XML????????????п???????ó?????????????XML????????XML?????????????κ?????????????ó??????XML???????????XML???????????£?

????Input -> XML doc == XML injection

?????? SSI???

????Web????????????????????HTML?????????С?????????????????????????????????????????????????SSI????????????????????SSL????????????п???????ó????????SSI????????????????????????????????????????HTML??????????????д???