### 简要描述:
该cms有xss漏洞 详见图
### 详细说明:
[<img src="https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg)
Destoon B2B网站系统
[<img src="https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg)
申请个帐号 然后购买广告
[<img src="https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg)
好像所有的广告都没过滤
[<img src="https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg" alt="4.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg)
随便点一个 直接插xss代码
[<img src="https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg" alt="5.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg)
本地登录后台 点刚才提交的广告
[<img src="https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg" alt="6.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg)
看到没 中招了
[<img src="https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg" alt="7.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg)
cookies到手
[<img src="https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg" alt="8.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg)
登录到后台
### 漏洞证明:
[<img src="https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231126241af821f04fd18fed8ed6a7ada801591b.jpg)
Destoon B2B网站系统
[<img src="https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311270035e9d0f608fdcd050500d1400a99bfbc.jpg)
申请个帐号 然后购买广告
[<img src="https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112737054c7b010e90bb43d0145d69a4c4d40f.jpg)
好像所有的广告都没过滤
[<img src="https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg" alt="4.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311281687b6adf41bb0400d7f0507b18701a277.jpg)
随便点一个 直接插xss代码
[<img src="https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg" alt="5.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311285204363eb3cf899125690fe859e59d06be.jpg)
本地登录后台 点刚才提交的广告
[<img src="https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg" alt="6.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/231129450e3c46e7473433dc63109adb3b3c1f11.jpg)
看到没 中招了
[<img src="https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg" alt="7.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/23112928e34a52ab8ee0cd73211b7fd6c009c736.jpg)
cookies到手
[<img src="https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg" alt="8.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201309/2311301723d02ffe36cb71389bec092a127e2559.jpg)
登录到后台
暂无评论