XSSxss
http://netsecurity.51cto.com/art/201408/448305_all.htmspa
检验: 输入<script>alert('xss')</script>,检查xxs存在性htm
预防: 对全部请求加上filter过滤ip