### 简要描述:
用户发帖时可以刷论坛积分。仅限于回贴有积分奖励的论坛,不过大部分貌似都存在这种漏洞
### 详细说明:
发帖时保存为草稿,前台后台都不显示,然后进入草稿可以回帖,回帖有奖励的论坛就会获得积分,回帖完了以后直接发表就能获得积分。
[<img src="https://images.seebug.org/upload/201407/3109343309faa75ab130cfa87c6659ea5ffbbdc6.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/3109343309faa75ab130cfa87c6659ea5ffbbdc6.png)
[<img src="https://images.seebug.org/upload/201407/31093449d38eb4c8444e96df796940e298ab9045.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/31093449d38eb4c8444e96df796940e298ab9045.png)
[<img src="https://images.seebug.org/upload/201407/310935006e291174963a9cb53b1fbf0c4cf04a51.png" alt="3.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/310935006e291174963a9cb53b1fbf0c4cf04a51.png)
[<img src="https://images.seebug.org/upload/201407/310936276bb2bfa44df96d5a4fe9a37c26375723.png" alt="4.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/310936276bb2bfa44df96d5a4fe9a37c26375723.png)
### 漏洞证明:
发帖时保存为草稿,前台后台都不显示,然后进入草稿可以回帖,回帖有奖励的论坛就会获得积分,回帖完了以后直接发表就能获得积分。
[<img src="https://images.seebug.org/upload/201407/3109343309faa75ab130cfa87c6659ea5ffbbdc6.png" alt="1.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/3109343309faa75ab130cfa87c6659ea5ffbbdc6.png)
[<img src="https://images.seebug.org/upload/201407/31093449d38eb4c8444e96df796940e298ab9045.png" alt="2.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/31093449d38eb4c8444e96df796940e298ab9045.png)
[<img src="https://images.seebug.org/upload/201407/310935006e291174963a9cb53b1fbf0c4cf04a51.png" alt="3.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/310935006e291174963a9cb53b1fbf0c4cf04a51.png)
[<img src="https://images.seebug.org/upload/201407/310936276bb2bfa44df96d5a4fe9a37c26375723.png" alt="4.png" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201407/310936276bb2bfa44df96d5a4fe9a37c26375723.png)
暂无评论